tomq_123
Give him six
- Joined
- Feb 3, 2010
- Messages
- 7,435
- Likes
- 13,833
This thing is crazy. We've had to update all our applications directly to both Log4J v. 2.15 and add in the JAVA_OPTS: -Dlog4j2.formatMsgNoLookups=true to all our applications. Hardest part has been tracing downstream dependencies that might run on the same JVM (AppD, NewRelic, Datadog, etc....). Plus, we are now finding that our NodeJS apps might also be vulnerable due to downstream dependency agents.