Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2021-44228] Log4Shell, The Worst Java Vulnerability in Years

bugcrowd.com | vulnerability | CVE-2021-44228 | #rce | #supply-chain | #zero-day | #java | #log4j | #log4shell | #cve-2021-44228

Summary

Log4Shell (CVE-2021-44228) is a 10.0-critical RCE affecting Apache Log4j 2.0-beta9 to 2.14.1, hitting Apple, Cloudflare, Twitter, and Minecraft—considered worse than the 2017 Apache Struts flaw.
Published
Collected

original ↗

Related coverage

back