APACHE LOG4J VULNERABILITY
DOI:
#10.25215/8119070682.06Keywords:
Vulnerability, log4j, RCEAbstract
Apache Log4j2 is a widely used logging library for Java-based applications. In December 2021, several critical and severe software vulnerabilities, including CVE-2021-44228, were publicly disclosed, allowing remote code execution (RCE) and denial of service (DoS) attacks. To date, these vulnerabilities are considered critical and the consequences of their disclosure are far-reaching. The vulnerabilities potentially affect a wide range of Internet-of-Things (IoT) devices, embedded devices, and cyber-physical systems. In this paper, we explore the fundamental concepts of log4j and when these vulnerabilities are discovered. We also examine the areas where vulnerabilities are assessed with CVSS scores that are becoming known around the world.
Metrics
Published
How to Cite
Issue
Section
License
Copyright (c) 2023 Sanjeevraddi. M. Satyaraddi, Preetham D, Manimozhi R

This work is licensed under a Creative Commons Attribution 4.0 International License.