Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
35% of Log4j downloads are grabbing the vulnerable version (gonze.com)
19 points by lucasgonze on May 3, 2022 | hide | past | favorite | 4 comments


Begging the question of why the vulnerable version is still available to be grabbed in the first place?


Deleting them would break builds ;)


this, companies who are hosting known vulnerable libraries should be charged criminally imo


That's one of the open questions. YES. Absolutely.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: