Vulnerability Management, Patch/Configuration Management, Threat Intelligence

Widespread Log4Shell compromise lingers, report finds

Infosecurity Magazine reports that 40 million Log4j instances, or 13% of all installations this year, remained susceptible to the maximum severity Log4Shell vulnerability four years after its emergence.

India accounted for the bulk of Log4Shell downloads, followed by China, Japan, and the U.S., according to a Sonatype analysis. Additional analysis revealed the persistence of other open source vulnerabilities, with nearly 95% of flawed downloaded releases already having a fix. Continued downloads of vulnerable packages have been attributed to set-and-forget dependencies, transitive dependency blind spots, and faulty library selection criteria, exacerbated by alerts with insufficient actionable guidance from software composition analysis tools.

Such findings should prompt developers to leverage SCA tools and artifact repositories to be more aware of vulnerable downloads; emphasize security, active maintenance, transparency, and governance in component selection; and automate upgrade pull requests. Developers have also been urged to establish tighter artifact repository and CI/CD pipeline controls, as well as additional metrics gauging policy effectiveness and risk rates.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds