Log4Shell: Critical Log4j RCE Vulnerabilty -- Update to Version 2.15.0
On Dec.10, 2021, a new, critical Log4j vulnerability was disclosed: Log4Shell. All current versions of log4j2 up to 2.14.1 are vulnerable.

Java Champions & Developer Advocate and Software Engineer for Snyk. Passionate about Java, (Pure) Functional Programming, and Cybersecurity. Co-leading the Virtual JUG, NLJUG and DevSecCon community. Brian is also an Oracle Groundbreaker Ambassador and regular international speaker on mostly Java-related conferences.
1 views
Brian Vermeer
6,498 viewsOn Dec.10, 2021, a new, critical Log4j vulnerability was disclosed: Log4Shell. All current versions of log4j2 up to 2.14.1 are vulnerable.
Brian Vermeer
6,120 viewsThe Java 17 LTS release brings you significant improvements to prevent malicious deserialization in your java applications.
Brian Vermeer
3,320 viewsOur research team found a correlation between socially trending vulnerabilities and the existence of exploits that can harm your …
Brian Vermeer
4,349 viewsA discussion with some great folks in the Java world about the highlights of the Snyk Java Ecosystem report and current developments in …

Brian Vermeer
13,790 viewsIf you are still running on an old Maven version like 3.6.3 or below, you need to upgrade to version 3.8.1 because of security reasons.

Brian Vermeer
5,743 viewsLearn how to begin with Snyk for secure Java development so that you too can be more secure from the get-go!

Brian Vermeer
6,563 viewsJVM Ecosystem Report 2021 presents the results of the largest annual survey on the state of the JVM ecosystem.
Brian Vermeer
7,178 viewsWhat is a strong encryption algorithm today, might be a weak algorithm a year from now. Therefore, encryption needs to be reviewed …
Brian Vermeer
9,849 viewsCross-site scripting (XSS) is a well-known issue and mostly utilized in JavaScript applications. However, Java is not immune to this!
Brian Vermeer
4,009 viewsWith anchors, you can create a YAML bomb! The tremendous amount of (nested) objects will cause a memory overload.