Log4Shell: The Vulnerability That Broke the Internet
How a feature in a logging library used by billions of devices became the most critical security vulnerability ever discovered.
The challenge
Log4j is a Java logging library used by virtually every Java application — from enterprise software to Minecraft servers to Tesla cars. In December 2021, a researcher discovered that Log4j's message lookup feature could be exploited to force any vulnerable system to execute arbitrary code from a remote attacker's server by simply sending a crafted string in any logged input.
The strategy
The vulnerability — CVE-2021-44228, nicknamed Log4Shell — required zero authentication. An attacker just needed to send a malicious string that got logged. Because Log4j was so ubiquitous and deeply embedded in software supply chains, most organizations didn't even know which of their systems were vulnerable. The attack surface was essentially the entire internet.
Want the full story, outcome and quiz?
Read how Log4Shell executed it, the results, key lessons and test yourself with a quiz. Free on CaseLearn.
Try the full case free →Key lessons (preview)
- Open-source dependencies deep in your software supply chain are attack surfaces you may not know exist.
- Powerful features in widely used libraries can become catastrophic vulnerabilities.
- Software supply chain security is not optional — you must know every library you depend on.
