Log4j Vulnerability Activity on the HackerOne Platform
ID: f34b8f32-0289-5b0c-b99f-6afc25f966fc
STIX ID: report--f34b8f32-0289-5b0c-b99f-6afc25f966fc
Feed Name: HackerOne Blog
Threat Score
This HackerOne post details the severe Log4j vulnerabilities (initially CVE-2021-44228 and the later CVE-2021-45046), explains the technical risk (unauthenticated RCE, CVSS 10), documents active exploitation and high attack volume, summarizes HackerOne submission statistics and customer responses, and provides mitigation and bug-bounty guidance (including upgrading to Log4j 2.16.0 and expanding/incentivizing program scope).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
