Critical Vulnerabilities 2021 Incident #54 CVE-2021-44228

Log4Shell (CVE-2021-44228)

Estimated Financial Impact
$5-17B+
Blast Radius
CVSS 10.0; 93% of cloud environments vulnerable

What Happened

A CVSS 10.0 RCE vulnerability in Apache Log4j 2 allowed attackers to execute arbitrary code by sending a crafted string to any application logging user input. The bug had existed since 2013 and affected virtually every Java enterprise application. 93% of cloud environments were vulnerable. Active exploitation began within hours including by nation-state actors and ransomware groups. CISA estimated full remediation would take a decade.

Sources: Cloudflare response · Rapid7 response

✓

Risk Guard: Caught

SOURCE_FEW_CONTRIBUTORS flagged under-maintained status years before; VULN_RECENT_FREQUENCY at disclosure

Risk Guard Check Codes That Flag This Incident

VULN_HISTORICAL_SEVEREVULN_RECENT_FREQUENCYSOURCE_FEW_CONTRIBUTORS

How Every Tool Performed

1 Caught 0 Partial 5 After damage 0 Missed
Tool Verdict Details
OSS Risk Guard Caught SOURCE_FEW_CONTRIBUTORS flagged under-maintained status years before; VULN_RECENT_FREQUENCY at disclosure
Socket After damage Detects after CVE published
Snyk After damage CVE detection after publication; does not flag maintainer risk beforehand
Sonatype (Nexus) After damage Detects after CVE published
Black Duck After damage Detects after CVE published
Endor Labs After damage CVE detection + reachability analysis after publication; reactive
← MavenGate Heartbleed (CVE-2014-0160) →