A CVSS 10.0 RCE vulnerability in Apache Log4j 2 allowed attackers to execute arbitrary code by sending a crafted string to any application logging user input. The bug had existed since 2013 and affected virtually every Java enterprise application. 93% of cloud environments were vulnerable. Active exploitation began within hours including by nation-state actors and ransomware groups. CISA estimated full remediation would take a decade.
Sources: Cloudflare response · Rapid7 response
SOURCE_FEW_CONTRIBUTORS flagged under-maintained status years before; VULN_RECENT_FREQUENCY at disclosure
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | SOURCE_FEW_CONTRIBUTORS flagged under-maintained status years before; VULN_RECENT_FREQUENCY at disclosure |
| Socket | After damage | Detects after CVE published |
| Snyk | After damage | CVE detection after publication; does not flag maintainer risk beforehand |
| Sonatype (Nexus) | After damage | Detects after CVE published |
| Black Duck | After damage | Detects after CVE published |
| Endor Labs | After damage | CVE detection + reachability analysis after publication; reactive |