eclipse-arrowhead / core-java-spring

Eclipse Public License 2.0
26 stars 51 forks source link

CVE-2021-44228 - Log4Shell log4j vulnerability #366

Closed BlackRose01 closed 2 years ago

BlackRose01 commented 2 years ago

Hello,

Please have a look on this vulnerability which concerning log4j. In germany, the BSI (Federal Office for Information Security) has given the vulnerability a warning level of 4/red. This is one of the highest warning levels that the BSI can assign.

4/Red stands for: The IT threat situation is extremely critical. Failure of many services, regular operation cannot be maintained.

KR, BlackRose

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228 https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/ https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592

Warning from BSI (german)

tsvetlin commented 2 years ago

Fixed by: #365