1.
hackerone.com | vulnerability | | original ↗ | #bug-bounty | #zero-day | #vulnerability-management | #java
HackerOne's coverage of Log4Shell: the incomplete 2.15.0 patch led to CVE-2021-45046, upgraded to critical (CVSS 9.0), with advice to upgrade to Log4j 2.16.0 and add Log4j bugs to bounty scope.
Skip to content