Apache Log4j Vulnerability Guidance¶
Cybersecurity and Infrastructure Security Agency (CISA). (2021). Apache Log4j Vulnerability Guidance.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Inherited-Substrate Risk
- Software supply chain: dependency-import attacks (Log4Shell, the xz-utils backdoor, typosquatting, the SolarWinds build compromise) propagate a defect in inherited substrate into thousands of downstream systems whose audit boundaries did not reach it; SBOM mandates, SLSA, and package signing are the substrate-provenance interventions.
This sourceDocuments the supply-chain reach of Log4Shell across transitively-dependent systems and the SBOM-based mitigation response.
- Software supply chain: dependency-import attacks (Log4Shell, the xz-utils backdoor, typosquatting, the SolarWinds build compromise) propagate a defect in inherited substrate into thousands of downstream systems whose audit boundaries did not reach it; SBOM mandates, SLSA, and package signing are the substrate-provenance interventions.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:16337dfa64e7 · see in the full table