log4j and learning from dependencies
A few weeks ago, the ubiquitous Java logging library log4j was found to have a severe security vulnerability with no available patch.
From the library's Wikipedia summary:
On December 9, 2021, a zero-day vulnerability involving arbitrary code execut...
spees.hashnode.dev5 min read