[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf

上传人:任我行 文档编号:31889 上传时间:2022-06-24 发布时间:2022-02-07 格式:PDF 页数:3 大小:694.87KB
下载 相关 举报
[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf_第1页
第1页 / 共3页
[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf_第2页
第2页 / 共3页
[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf_第3页
第3页 / 共3页
亲,该文档总共3页,全部预览完了,如果喜欢就下载吧!
资源描述

1、CRS INSIGHT Prepared for Members and Committees of Congress INSIGHTINSIGHTi i Systemic Vulnerabilities in Information TechnologyLog4Shell Updated February 7, 2022 There is critical vulnerability in software used by millions of internet servers. Since its discovery both criminals and nation-state act

2、ors have reportedly exploited it. It is uncertain how many entities are vulnerable, but it is presumed there are many. This CRS Insight describes the vulnerability and federal government response considerations. Log4Shell Log4j is an open-source tool the Apache Foundation makes available for logging

3、 web server activity. To work, Log4J has to access many network services (e.g., network maps and directories). Malicious actors discovered a way to use the Log4j tool to send commands that give them control of the servers. The cybersecurity community named this vulnerability Log4Shell. Log4Shell exp

4、loits have been observed to mine cryptocurrencies and expand botnets. Apache Foundation software is very useful and freely available, so it is widely deployed. Hundreds of software projects maintained by the foundation rely on volunteer developers and are supported by donations and sponsorships. Res

展开阅读全文
相关资源
猜你喜欢
相关搜索
资源标签

当前位置:首页 > 法规条令 > CRS 美国国会研究处报告