Navigation
Search
|
Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16
Wednesday December 15, 2021. 12:30 AM , from TheRegister
Now open-source logging library's JNDI disabled entirely by default, message lookups removed
Last week, version 2.15 of the widely used open-source logging library Log4j was released to tackle a critical security hole, dubbed Log4Shell, which could be trivially abused by miscreants to hijack servers and apps over the internet.…
https://go.theregister.com/feed/www.theregister.com/2021/12/14/apache_log4j_v2_16_jndi_disabled_defa...
|
25 sources
Current Date
Apr, Sun 28 - 21:10 CEST
|