Log4Shell, the computer flaw has been closed completely

The CDM has approved the new decree on quarantines and super green pass (ANSA)

(ANSA) – MILAN, 30 DEC – Log4Shell, the computer bug that has kept companies and organizations in suspense of the current year, has been definitively closed. Experts say this after the release of the latest update for Log4J by the Apache Software Foundation. It is the non-profit foundation behind the development of the vulnerable code library, the technical foundation on which global services and apps, such as Amazon and Twitter, rest. With the release of the 2.17.1 update, the flaw is resolved, as well as the persistent security problems that characterized the previous version, 2.16.0, widespread in the days immediately following the discovery of the bug. Log4Shell, as it emerged earlier this month, allowed external users to hack vulnerable platforms, leaving no trace of their moves. According to the analysis of computer experts, there have been over 4 million attempts to exploit the vulnerability. In particular, for Check Point Research, since it was made public, 43% of corporate networks in Italy have suffered an attack connected to Log4Shell. In practice, almost one in two companies in our country has been affected. And it is the reason why the Italian cybersecurity agency had also asked for a lot of attention on the issue. Version 2.17.1 focuses on the vulnerability known as CVE-2021-44832, which could cause unauthorized code execution by those already inside the hacked system, using the Log4j library.

This is, as the researchers explain, an unlikely scenario, so much so that the bug has been assigned a moderate level of danger. This does not mean that it is not important to update, also because at the moment it is not known if it is possible, for third parties, to exploit some other flaw present in 2.16.0, and not yet identified. (HANDLE).

.

Source From: Ansa

Share this article:

Leave a Reply

most popular