Skip to content

Proposal: Case Study on Log4Shell (CVE-2021-44228) #73

@purnaadithya

Description

@purnaadithya

Description:

We propose to create a secure coding case study on the Log4Shell vulnerability (CVE-2021-44228) in Apache Log4j.

This vulnerability allowed attackers to execute remote code by sending specially crafted input that gets logged by an application.

It is an important case because it affected many systems and highlights how unsafe logging features can lead to serious security issues.

This vulnerability is associated with CWE-917 and CWE-74.

Team Members:

  • Purna Adithya Akula (G01588237)
  • Veera Venkata Satya Siddhartha Gopalam (G01551529)

We plan to proceed with this case study unless there are objections.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions