Apache Log4j
DEC 09 2021
The Apache Log4j logo. Log4Shell (CVE-2021-44228), disclosed 9 December 2021, let an attacker run arbitrary code on any Java service that logged a hostile string, and Log4j was inside a very large share of the world's enterprise software. It is the defining software-supply-chain incident: a single unpaid volunteer library at the base of a global stack.
Source: Wikimedia Commons
Part of Cybersecurity · Watch in the documentary
