<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Karsten Silz on foojay.io - Friends of OpenJDK</title><link>https://foojayio.github.io/website/today/author/karsten-silz/</link><description>Articles written by Karsten Silz on foojay.io - Friends of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 10 Jan 2022 10:03:24 +0000</lastBuildDate><atom:link href="https://foojayio.github.io/website/today/author/karsten-silz/index.xml" rel="self" type="application/rss+xml"/><item><title>Log4Shell Shows The Need for "Trustworthy Java"</title><link>https://foojayio.github.io/website/today/log4shell-shows-the-need-for-trustworthy-java/</link><pubDate>Mon, 10 Jan 2022 10:03:24 +0000</pubDate><guid>https://foojayio.github.io/website/today/log4shell-shows-the-need-for-trustworthy-java/</guid><description>&lt;h2 id="h2-0-what-just-happened"&gt;What Just Happened?&lt;/h2&gt;
&lt;p&gt;I believe Log4Shell is Java&amp;rsquo;s biggest crisis. I reported on it in the &amp;ldquo;&lt;a href="https://betterprojectsfaster.com/guide/java-full-stack-report-2022-01-new-noteworthy" target="_blank" rel="noopener noreferrer"&gt;New &amp;amp; Noteworthy&lt;/a&gt;
&amp;rdquo; section of &lt;a href="https://bpfnl.substack.com" target="_blank" rel="noopener noreferrer"&gt;my newsletter&lt;/a&gt;
. A quick recap: The US cybersecurity and infrastructure agency director &lt;a href="https://www.zdnet.com/article/log4j-flaw-this-new-threat-is-going-to-affect-cybersecurity-for-a-long-time/" target="_blank" rel="noopener noreferrer"&gt;called Log4Shell&lt;/a&gt;
 &amp;ldquo;one of the most serious that I&amp;rsquo;ve seen in my entire career, if not the most serious&amp;rdquo;. Exploiting it may be as easy as sending an HTTP request to a Java application, with a JNDI link in the HTTP header. The last wide-spread software vulnerability of this magnitude &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0160" target="_blank" rel="noopener noreferrer"&gt;scored 7.5&lt;/a&gt;
 - Log4Shell &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228#" target="_blank" rel="noopener noreferrer"&gt;scored a 10&lt;/a&gt;
.&lt;/p&gt;</description></item></channel></rss>