paint-brush
What the Log4j Incident Means for Open Source and the Entire Internet by@vinckr
1,047 reads
1,047 reads

What the Log4j Incident Means for Open Source and the Entire Internet

by Ory4mDecember 18th, 2021
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

This article discusses the log4j incident, why people are worried about the open-source software (OSS) supply chain, and how to work towards fixing it. The Spark: Log4Shell Last week (Dec 9th) a major vulnerability was discovered in an open-source logging project for Java called log4j. The vulnerability called Log4Shell would allow anyone to remotely run arbitrary code if they sent a message in the right format to the server. This is one of the worst attacks your system can be susceptible to and if you are interested in the technical details of the problem, here is an overview. The attack surface of Log4Shell is staggering. Amazon, Apple, Google, and the Apache Server are affected; it can almost not get bigger than this. We will see the real fallout of Log4Shell in the upcoming weeks and months as right now servers worldwide are being scanned and prodded for this vulnerability.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail

Coin Mentioned

Mention Thumbnail
featured image - What the Log4j Incident Means for Open Source and the Entire Internet
Ory HackerNoon profile picture
Ory

Ory

@vinckr

Ory is the only authentication and authorization platform based entirely on open source.

About @vinckr
LEARN MORE ABOUT @VINCKR'S
EXPERTISE AND PLACE ON THE INTERNET.
L O A D I N G
. . . comments & more!

About Author

Ory HackerNoon profile picture
Ory@vinckr
Ory is the only authentication and authorization platform based entirely on open source.

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite