CISA Issues Statement on Log4j Critical Vulnerability

Alston & Bird
Contact

Alston & Bird

Log4j is a java-based tool from Apache’s open source library used for parsing logs that never seems to have made headlines before this past weekend.  Now, following the December 9th public announcement of a vulnerability in this tool, public and private sector security partners are issuing warnings about this “critical vulnerability.”  While the full scope and exploitability of this vulnerability remains to be seen, the Cybersecurity and Infrastructure Agency (“CISA”) has issued a statement that they are taking “urgent action.”  Noting this vulnerability “poses a severe risk,” CISA “is proactively reaching out to entities whose networks may be vulnerable,” and is leveraging it scanning and intrusion detection tools “to help government and industry partners identify exposure to or exploitation of the vulnerability.”  While CISA has issued basic guidance (including to patch any known externally-facing uses of Log4j), we can expect more intelligence and mediation recommendations in the coming days and weeks.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Alston & Bird | Attorney Advertising

Written by:

Alston & Bird
Contact
more
less

Alston & Bird on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide