Provides a case study on the persistence of critical vulnerabilities and the extreme labor cost and regression risk associated with transitive dependency remediation.
One year after the discovery of Log4Shell, 72% of organizations worldwide remain vulnerable, and 25% of Log4j instances downloaded from Maven Central are still vulnerable versions. Transitive dependencies are a major obstacle, with 174,000 projects using Log4j transitively—more than double the 70,000 using it as a direct dependency. Despite federal emergency directives giving agencies one week to patch, state-sponsored actors successfully exploited unpatched servers months later. Research shows that 29% of assets initially remediated saw a reintroduction of the vulnerability when new systems or insecure builds were added to the environment. Incident response costs averaged $90,000 per event, with some organizations spending over 33,000 hours on response efforts.
25% of Log4j downloads from Maven Central are still vulnerable versions a year after disclosure, despite patched versions being available from day one.
deliberate or accidental inclusion of specific vulnerable versions in new builds when patched alternatives exist
flagging known vulnerabilities in the specific version being consumed is the direct defense against the persistent download of vulnerable Log4j versions documented in this report.
29% of these assets had recurrences of Log4Shell after full remediation was achieved... reintroductions happen anytime developers add new systems.
Risk Guard scans the current state but does not provide 'Drift Detection' to alert when a previously remediated vulnerability reappears in a dependency graph.
Risk Guard would be better if it maintained a 'Remediation History' for a project and flagged any regressions where a fixed version is downgraded to a vulnerable one.