Don’t do SECURITY. Do business SECURELY.

Log4Shell flaw in Log4j puts millions of systems at risk

A critical flaw in the widely used Apache Log4j logging library, dubbed Log4Shell, triggers a worldwide scramble to patch.

A critical vulnerability in Apache Log4j, a Java logging library used in countless applications and services, was disclosed publicly and quickly exploited. Tracked as CVE-2021-44228 and nicknamed Log4Shell, it let attackers run code remotely simply by getting a crafted string logged.

What happened

  • The flaw had been reported privately to Apache in November 2021 by a researcher at Alibaba Cloud.
  • Exploit code circulated publicly on 9 December, and Apache released a fix the next day.
  • Attackers began mass scanning within hours, including cryptominers, botnets, and ransomware groups.
  • CISA’s director described it as one of the most serious vulnerabilities she had seen in her career.

Why it mattered

Log4Shell showed how deeply organisations depend on open-source components they may not know they use, and pushed software bills of materials up the agenda. Governments warned that vulnerable systems would remain at risk for years because Log4j is embedded in so many products.

Lessons for organisations

Maintain an accurate inventory of software and components, including open-source libraries, and have a process to find and patch affected systems quickly. Ask suppliers to confirm their exposure. Web application firewalls and egress filtering can reduce exposure while patches are rolled out.

Source: CISA

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights