Log4j
Posted: 2021-12-13 22:30
This Log4j seems like a nice little disaster.
Every few years there is a big hole like this. Annoying.



I hate to say this, but why the fuck would you want to use Java in this way?In an interview, Johannes Ullrich, dean of research at the SANS Institute, predicted it will take years for organizations and cloud providers to patch their applications to close this hole. Oracle is still patching some of its applications from different log4j vulnerabilities discovered several years ago, he pointed out.