Two years on, 1 in 4 apps still vulnerable to Log4Shell
ID: 141b3cfc-0213-5029-8c61-f78b6f8ed63d
STIX ID: report--141b3cfc-0213-5029-8c61-f78b6f8ed63d
Feed Name: The Register (Security)
Two years after the Log4Shell disclosure, Veracode and Sonatype research shows that a large portion of software remains exposed: roughly 35% of applications are still vulnerable to Log4Shell and nearly 40% are vulnerable to RCE flaws due to outdated Log4j versions, with 26% of recent Log4j downloads containing vulnerable releases; while many organizations patched quickly and exploitation was limited, the report highlights persistent risk from unpatched dependencies and some documented attacks using the flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
