Apache releases Log4j version 2.16.0 to Disable Java Naming and Directory Interface. If successfully exploited, the zero-day flaw can be used for remote code exploitation. Security teams have gone into overdrive to assess the risk facing their organizations. The flaw, designated CVE-2021-44228 and also known as the Log4Shell vulnerability, is “about as serious as it gets,” says Cybereason CSO Sam Curry. It’s too soon to say whether this might rank as the worst vulnerability of the decade, he says.”]
Source: https://www.govinfosecurity.com/exploiting-log4j-40-corporate-networks-targeted-so-far-a-18120

