Apache's Log4J patch to fix an exploit had two vulnerabilities of its own

mylesillidge

Journalist
Joined
Jul 29, 2021
Messages
4,275
Reaction score
4,577
Fix for Log4J exploit has its own vulnerabilities

Open-source developers released a patch for a severe vulnerability in Apache's Log4J, and the fix has been discovered to have two vulnerabilities of its own.

According to a report from Ars Technica, the fix allowed attackers to execute denial-of-service attacks, making it easy to take vulnerable services offline until they reboot their servers.
 
Top
Sign up to the MyBroadband newsletter
X