PSA: Major Java Vulnerability in Log4J and Actionable Links

roydan

Elite Member
Joined
Dec 17, 2013
Messages
5,618
Reaction score
14,572
Just got this email from Wordfence, you should act fast if it concerns you:


I'm taking the unusual step of sending out a quick email alert about a very bad Java vulnerability in log4j. PHP and WordPress are our wheelhouse at Wordfence, but this is so bad, that I'm sending this alert with resources to help our Java friends lock things down fast.



Hopefully, you've all seen this vulnerability in the news already, but in case not, I'm going to link to a collection of resources rather than writing a blog post, because others have already covered this story. If you are developing or running any Java-based web applications, you need to move fast to fix this. It's bad and will have a wide impact.

This rather catastrophic vulnerability affects anything that uses log4j to log anything that includes user input. And that means it affects nearly every Java application that accepts input from the Web.



Move fast, use the links above to get up to speed, and secure your Java applications. This is Javageddon folks. Best of luck.
 
I received an email from shopify partners, I was playing with making an app based on their example but I don't know if it uses java.
 
Back
Top