MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
log
Recherche

Understanding the Impact of Apache Log4j Vulnerability (Google)

vendredi 17 décembre 2021, 18:52 , par LWN.net
The Google Security Blog looks
into the ripple effects of the Log4j vulnerability.

Most artifacts that depend on log4j do so indirectly. The deeper
the vulnerability is in a dependency chain, the more steps are
required for it to be fixed. The following diagram shows a
histogram of how deeply an affected log4j package (core or api)
first appears in consumers dependency graphs. For greater than 80%
of the packages, the vulnerability is more than one level deep,
with a majority affected five levels down (and some as many as nine
levels down). These packages will require fixes throughout all
parts of the tree, starting from the deepest dependencies first.
https://lwn.net/Articles/879052/rss
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Date Actuelle
jeu. 25 avril - 10:25 CEST