eDiscovery Data Points from ComplexDiscovery

Assessment and Advice: ENISA Update on Log4j Vulnerability


Listen Later

On December 9th, information about a critical unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2021-
44228) that is affecting the well-known Java logging package Log4j used by many popular applications and web services was tweeted along with a proof-of-concept (PoC) posted on GitHub. This vulnerability could allow the attacker full control of the affected server if a user-controlled string is logged. Since it is easy to be exploited, the impact of this vulnerability is quite severe. This ENISA overview and updated CERT-EU security advisory may be beneficial for cybersecurity, information governance, and legal discovery professionals in the eDiscovery ecosystem facing the challenge of this vulnerability.
The post Assessment and Advice: ENISA Update on Log4j Vulnerability appeared first on ComplexDiscovery.
...more
View all episodesView all episodes
Download on the App Store

eDiscovery Data Points from ComplexDiscoveryBy ComplexDiscovery Blog

  • 5
  • 5
  • 5
  • 5
  • 5

5

1 ratings