Log4j Vulnerability

In News 

A new vulnerability named Log4 Shell is being touted as one of the worst cybersecurity flaws to have been discovered. 

About Log4j vulnerability

  • The vulnerability is dubbed Log4 Shell and is officially CVE-2021-44228.
    • CVE number is the unique number given to each vulnerability discovered across the world).
  • It is based on an open-source logging library used in most applications by enterprises and even government agencies.
  • The exploits for this vulnerability are already being tested by hackers and it grants them access to an application, and could potentially let them run malicious software on a device or servers.
  • The problem impacts Log4j 2 versions which is a very common logging library used by applications across the world. 
    • Logging lets developers see all the activity of an application.
  • Concerns: 
  • It is a serious concern because it could allow hackers to control java-based web servers and launch what is called ‘remote code execution (RCE) attacks.
    • In simple words, the vulnerability could allow a hacker to take control of a system.
    • It is rating this vulnerability as quite severe.
      • the flaw “can be exploited either over HTTP or HTTPS (the encrypted version of browsing),” which adds to the problems.

Source: IE

 

Other News of the Day

In News ‘Solar Hamam’ takes care of heating in cold Himalayan regions especially in the villages of Ladakh, Himachal Pradesh and Uttarakhand. The Solar Hamam had won the “Himachal Pradesh State Innovation Award for 2016-17”. What is Solar Hamam? About: The Solar Hamam provides an anti-freezing outlet. It provides for 15-18 litres of boiling hot...
Read More

In News  Recently, the Prime Minister of India and several Union Ministers paid tribute to Sardar Vallabhbhai Patel on his 71st death anniversary. Sardar Vallabhbhai Patel (1875-1950) Birth:  At Nadiad, Gujarat on 31st October 1875. In 2014, the Government decided to celebrate his birthday as National Unity Day to honour his contribution to integrating and...
Read More

In News The Centre has approached the Supreme Court seeking modification of its order directing that all transmission cables in the habitat of the Great Indian Bustard (GIB) be laid underground. Earlier in 2021, SC has directed that overhead power lines be laid underground wherever feasible. Challenges/ Difficulties in Implementation It has implications for the...
Read More

In News The Reserve Bank of India (RBI) has decided to bring non-banking finance companies (NBFCs) under the ambit of the prompt corrective action (PCA) framework. About RBI had introduced a PCA framework for scheduled commercial banks in 2002 and the same has been reviewed from time to time. Changes made in NBFC sector Time...
Read More

In News The Narcotic Drugs and Psychotropic Substances (Amendment) Bill, 2021 was passed by Lok Sabha. About It seeks to replace the Narcotic Drugs and Psychotropic Substances (Amendment) Ordinance, 2021. Background The error: was noticed by a district judge in West Agartala. In 2016: an accused had sought bail before a special judge in West...
Read More

Context  The Leh Apex Body and Kargil Democratic Alliance seek constitutional safeguards for Ladakh on the lines of the Sixth Schedule of the Constitution.  The demand came a day after the region observed a complete shutdown demanding statehood and protection for land and jobs. Background  On August 5, 2019, the erstwhile state of Jammu and...
Read More

In News Recently, the World Trade Organisation dispute resolution panel has ruled against India’s sugar subsidies, and in favour of complainants Brazil, Guatemala and Australia. Background In 2019, Brazil, Australia and Guatemala had approached the WTO complaining against India for providing alleged support in favour of producers of sugarcane and sugar (domestic support measures), as...
Read More