Infosecurity Magazine reports that 40 million Log4j instances, or 13% of all installations this year, remained susceptible to the maximum severity Log4Shell vulnerability four years after its emergence.India accounted for the bulk of Log4Shell downloads, followed by China, Japan, and the U.S., according to a Sonatype analysis. Additional analysis revealed the persistence of other open source vulnerabilities, with nearly 95% of flawed downloaded releases already having a fix. Continued downloads of vulnerable packages have been attributed to set-and-forget dependencies, transitive dependency blind spots, and faulty library selection criteria, exacerbated by alerts with insufficient actionable guidance from software composition analysis tools.Such findings should prompt developers to leverage SCA tools and artifact repositories to be more aware of vulnerable downloads; emphasize security, active maintenance, transparency, and governance in component selection; and automate upgrade pull requests. Developers have also been urged to establish tighter artifact repository and CI/CD pipeline controls, as well as additional metrics gauging policy effectiveness and risk rates.
Vulnerability Management, Patch/Configuration Management, Threat Intelligence
Widespread Log4Shell compromise lingers, report finds

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



