Company
Date Published
Author
-
Word count
450
Language
English
Hacker News points
None

Summary

The Apache log4j utility, known as log4shell, has been identified with a critical zero day vulnerability that allows arbitrary code execution on affected systems. Esper, an Android company, has no reason to believe it has been targeted and believes the exploitation of this vulnerability is unlikely due to the lack of native support for Java Naming and Directory Interface (JNDI) in Android. However, it's recommended to practice due diligence by checking with development teams and software vendors about their response to log4shell. Esper has already patched a small number of vulnerable tools in its own infrastructure, including the Apache Flink framework, and will continue to monitor the situation as it develops.