Review of the December 2021 Log4j Event¶
Cyber Safety Review Board. (2022). Review of the December 2021 Log4j Event.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Domain-specific¶
- Injection Weakness
- Because Log4j is embedded in vast numbers of Java applications, exploitation was immediate and global
This sourceThe federal post-incident review documenting Log4j's ubiquity and scanning and exploitation attempts that began within hours of disclosure, while finding actual exploitation lower than predicted.
Supported in partVerified against the source
- Because Log4j is embedded in vast numbers of Java applications, exploitation was immediate and global
Verification¶
Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.
Does it back the claim? Read against the text for 1 of 1 citation: 1 supported in part. Each verdict is shown under its citation below, with what in the work backs the sentence.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:9da4ab5ce635 · see in the full table