Episode 1 ยท 1:27
The Message Was Logged
Prefer to watch it? The same episode on YouTube.
Do not treat a logging library as harmless background plumbing. A vulnerable dependency can turn ordinary attacker-controlled text into code execution.
- Severity
- 10.0 Critical
- Vulnerability
- (Log4Shell)
- OWASP
- A06:2021 Vulnerable and Outdated Components
Do not treat a logging library as harmless background plumbing. A vulnerable dependency can turn ordinary attacker-controlled text into code execution.
Whale and Urchin discuss CVE-2021-44228 (Log4Shell) with the appropriate amount of corporate urgency: almost none. The episode runs 87 seconds.
The vulnerability#
CVE-2021-44228 (Log4Shell) is scored 10.0 Critical. It sits under A06:2021 Vulnerable and Outdated Components.
Sources#
The joke only works if the vulnerability is real. These are the primary records:
Transcript
Sources
The joke only works if the vulnerability is real. These are the primary records.