By J. Mesa
In December 2021, security teams around the world spent their holidays hunting for one small piece of software. A flaw in a logging tool called Log4j let an attacker take over a server by sending it a single line of text. The flaw got the name Log4Shell, and attackers still use it today.
You may never have heard of Log4j. Your business may still run it. This post explains what happened, who is at risk, and what to check.
What is Log4Shell?
Log4j is a free, open-source logging library for the Java programming language. Developers use it to record what an application does: who logged in, what a user searched for, which errors occurred. Thousands of commercial products include it, from web applications to network appliances.
Log4Shell is the name for a vulnerability in Log4j tracked as CVE-2021-44228. Researchers disclosed it on December 9, 2021. It received a severity score of 10 out of 10, the highest rating possible.
How does the Log4Shell attack work?
Log4j had a feature that looked up information whenever it found a special instruction inside a log message. An attacker could place that instruction anywhere the application would log it: a username field, a search box, a web request header.
- The attacker sends text containing a lookup instruction that points to a server the attacker controls.
- The application writes that text to its log.
- Log4j reads the instruction, connects to the attacker’s server, and downloads code.
- The application runs that code. The attacker now controls the system.
The attacker needs no password and no account. The industry calls this remote code execution, and it is the reason the score reached 10.
Why was Log4Shell so serious?
- It was everywhere. Log4j sat inside products from hundreds of vendors. Many companies did not know they used it.
- It was easy. Working attack code spread within hours of disclosure.
- It was hidden. Log4j often sits several layers deep inside other software, so finding it took weeks.
The director of the US Cybersecurity and Infrastructure Security Agency (CISA) at the time called it one of the most serious vulnerabilities she had seen in her career. Criminal groups and nation-state actors both used it. Botnets such as Mirai and Kinsing scanned the internet for vulnerable servers and installed malware, cryptocurrency miners, and ransomware.
Is Log4Shell still a threat?
Yes. Many organizations patched in 2021 and 2022. Many forgotten or unmanaged applications still run vulnerable versions, and attackers keep scanning for them. In 2022 the US Cyber Safety Review Board called Log4Shell an “endemic vulnerability” and warned that vulnerable copies would stay in systems for a decade or longer.
Old software does not fix itself. The server someone set up in 2019 and forgot is the one an attacker finds.
Am I affected if my business doesn’t write software?
You can be. You don’t need a developer on staff to run Java software. Log4j shipped inside products that small businesses buy and install, including:
- Network and security appliances
- Remote access and virtual desktop products
- Backup, monitoring, and help desk tools
- Line-of-business applications from smaller vendors
Cloud services you subscribe to were the vendor’s job to patch. Software and devices in your own office or server room are your job.
How do I check if I am vulnerable to Log4Shell?
- List what you run. Write down every server, appliance, and business application you own, with its version. You can’t patch what you don’t know about.
- Check vendor advisories. Search each vendor’s site for “Log4j” or “CVE-2021-44228.” Most published a statement and a fixed version.
- Scan. A vulnerability scan finds known-vulnerable versions of Log4j on your network. This is a standard part of a vulnerability assessment.
- Look for old systems. Pay attention to anything installed before 2022 that no one has updated since.
Vulnerable versions of Log4j run from 2.0-beta9 through 2.14.1.
How do I fix Log4Shell?
- Update the affected product to the vendor’s fixed release. For Log4j itself, that means version 2.17.1 or later on Java 8.
- If a vendor no longer supports the product, replace it or take it off the network.
- Limit which servers can make outbound connections to the internet. The attack depends on your server reaching out to the attacker.
- Watch your logs for the text
${jndi:, the marker of an attempted attack.
What did Log4Shell teach us?
- Know your software supply chain. You depend on code you never chose. Keep an inventory of the products you run and the components inside them.
- Patch fast. Attackers began exploiting Log4Shell within hours. A patch process that takes months leaves the door open.
- Detect and respond. You need a way to see an attack in progress and a tested plan for what to do next.
- Train your people. Staff who know how to report something odd shorten the time an attacker spends inside your network.
What should a small business do now?
- Build or update your inventory of systems and software.
- Turn on automatic updates wherever a product offers them.
- Schedule a vulnerability assessment at least once a year.
- Write a one-page incident response plan and walk through it with your team.
What is a software bill of materials, and do I need one?
A software bill of materials (SBOM) is an ingredient list for a piece of software. It names every component inside the product, including libraries such as Log4j. When the next Log4Shell arrives, a company with SBOMs can search them and know within minutes which products to patch.
You don’t need to build one yourself. Ask your software vendors whether they provide an SBOM, and ask how they notify customers about security fixes. A vendor with clear answers to both questions handled Log4Shell faster than one without. Add those two questions to your checklist when you buy new software.
Your next step
If you don’t know whether a vulnerable system sits on your network, find out before an attacker does. Cerberus Cybersecurity runs risk and compliance assessments that include vulnerability scanning and a plain-language report. Contact us to schedule one.

Leave a Reply