Category: Database, Security

How many of us are surprised to learn that yet another https://thenewstack.io/log4shell-we-are-in-so-much-trouble/y has been discovered? In my office, that would be a big, fat zero. We don’t like it mind you, but surprised? Heck no. The latest, https://logging.apache.org/log4j/2.x/security.html#:~:text=CVE-2021-44832, with a Common Vulnerability Scoring System (CVSS) rating of 6.6, moderate, isn’t awful.

If left unpatched, an attacker can use the vulnerability to conduct a RCE with the https://docs.oracle.com/javase/tutorial/jdbc/overview/index.html Appender.

Related Articles