Mitigating Log4Shell and Other Log4j-Related Vulnerabilities¶
Cybersecurity and Infrastructure Security Agency (CISA), FBI, & NSA. (2021). Mitigating Log4Shell and Other Log4j-Related Vulnerabilities.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Complete Enumeration
- When a widely used logging library was found critically vulnerable, organizations without complete SBOMs could not answer whether they were exposed
This sourceDocuments the Log4j (Log4Shell, CVE-2021-44228) incident and the difficulty organizations faced determining exposure given pervasive transitive use of the library — the case for complete dependency enumeration. (Resolves needs-source-011 with a security-incident/advisory reference.)
- When a widely used logging library was found critically vulnerable, organizations without complete SBOMs could not answer whether they were exposed
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:d1b5fbb327c9 · see in the full table