CaseLearn logo
CASELEARN
Education that works
Try free
Home › Case studies › Log4Shell
TechnologyEngineering FailureOpen Source / SecurityAdvanced2021

Log4Shell: The Vulnerability That Broke the Internet

How a feature in a logging library used by billions of devices became the most critical security vulnerability ever discovered.

The challenge

Log4j is a Java logging library used by virtually every Java application — from enterprise software to Minecraft servers to Tesla cars. In December 2021, a researcher discovered that Log4j's message lookup feature could be exploited to force any vulnerable system to execute arbitrary code from a remote attacker's server by simply sending a crafted string in any logged input.

The strategy

The vulnerability — CVE-2021-44228, nicknamed Log4Shell — required zero authentication. An attacker just needed to send a malicious string that got logged. Because Log4j was so ubiquitous and deeply embedded in software supply chains, most organizations didn't even know which of their systems were vulnerable. The attack surface was essentially the entire internet.

Want the full story, outcome and quiz?

Read how Log4Shell executed it, the results, key lessons and test yourself with a quiz. Free on CaseLearn.

Try the full case free →

Key lessons (preview)

More Engineering Failure cases

FacebookThe 6-Hour Outage — How DNS Took Down EverythingKnight Capital$440 Million Lost in 45 Minutes — The Costliest Bug in HistoryCrowdstrike8.5 Million Windows Machines Crashed by One UpdateTherac-25The Radiation Machine That Killed People Due to a Software Bug