A critical vulnerability in Apache Log4j, a Java logging library used in countless applications and services, was disclosed publicly and quickly exploited. Tracked as CVE-2021-44228 and nicknamed Log4Shell, it let attackers run code remotely simply by getting a crafted string logged.
What happened
- The flaw had been reported privately to Apache in November 2021 by a researcher at Alibaba Cloud.
- Exploit code circulated publicly on 9 December, and Apache released a fix the next day.
- Attackers began mass scanning within hours, including cryptominers, botnets, and ransomware groups.
- CISA’s director described it as one of the most serious vulnerabilities she had seen in her career.
Why it mattered
Log4Shell showed how deeply organisations depend on open-source components they may not know they use, and pushed software bills of materials up the agenda. Governments warned that vulnerable systems would remain at risk for years because Log4j is embedded in so many products.
Lessons for organisations
Maintain an accurate inventory of software and components, including open-source libraries, and have a process to find and patch affected systems quickly. Ask suppliers to confirm their exposure. Web application firewalls and egress filtering can reduce exposure while patches are rolled out.
Source: CISA
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.