Over 40% of Log4j Downloads Are Vulnerable Versions of the Software

siteadmin March 11, 2022


Three months after the Apache Foundation disclosed the infamous Lo4j vulnerability [CVE-2021-44228] and issued a fix for it, more than 4 in 10 downloads of the logging tool from the Maven Central Java package repository continue to be known vulnerable versions.
A dashboard that Maven Central…

Source: www.darkreading.comRead more