APACHE LOG4J VULNERABILITY

Authors

  • Sanjeevraddi. M. Satyaraddi
  • Preetham D
  • Manimozhi R

DOI:

#10.25215/8119070682.06

Keywords:

Vulnerability, log4j, RCE

Abstract

Apache Log4j2 is a widely used logging library for Java-based applications. In December 2021, several critical and severe software vulnerabilities, including CVE-2021-44228, were publicly disclosed, allowing remote code execution (RCE) and denial of service (DoS) attacks. To date, these vulnerabilities are considered critical and the consequences of their disclosure are far-reaching. The vulnerabilities potentially affect a wide range of Internet-of-Things (IoT) devices, embedded devices, and cyber-physical systems. In this paper, we explore the fundamental concepts of log4j and when these vulnerabilities are discovered. We also examine the areas where vulnerabilities are assessed with CVSS scores that are becoming known around the world.

Metrics

Metrics Loading ...

Published

2023-06-30

How to Cite

Sanjeevraddi. M. Satyaraddi, Preetham D, & Manimozhi R. (2023). APACHE LOG4J VULNERABILITY. Redshine Archive, 1. https://doi.org/10.25215/8119070682.06