<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Spring4Shell Bug - yes another Log4J issue in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50322#M502</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like another Spring for Java development has sprung up, even though it is Autumn in the Southern Hemisphere.&amp;nbsp; It looks very much another extension to Log4J and Spring for Cloud with serious consequences.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatpost.com/critical-rce-bug-spring-log4shell/179173/" target="_blank" rel="noopener"&gt;https://threatpost.com/critical-rce-bug-spring-log4shell/179173/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 10:08:31 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2023-10-09T10:08:31Z</dc:date>
    <item>
      <title>Spring4Shell Bug - yes another Log4J issue</title>
      <link>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50322#M502</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like another Spring for Java development has sprung up, even though it is Autumn in the Southern Hemisphere.&amp;nbsp; It looks very much another extension to Log4J and Spring for Cloud with serious consequences.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatpost.com/critical-rce-bug-spring-log4shell/179173/" target="_blank" rel="noopener"&gt;https://threatpost.com/critical-rce-bug-spring-log4shell/179173/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:08:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50322#M502</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Spring4Shell Bug - yes another Log4J issue</title>
      <link>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50365#M505</link>
      <description>&lt;P&gt;Yes, will be another busy week.... there are 2 related CVEs and the RCE is really bad, even worst than the log4shell&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/" target="_blank"&gt;https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;virtual patching and patching...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 15:18:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50365#M505</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2022-04-01T15:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Spring4Shell Bug - yes another Log4J issue</title>
      <link>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50381#M506</link>
      <description>&lt;P data-unlink="true"&gt;Here is an analysis (one of many out there) that describes the similarities with Log4j. This one describes the &lt;A href="https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities/" target="_blank" rel="noopener"&gt;exploit scenario&lt;/A&gt; associated with Spring Core and the dependencies&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 12:50:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50381#M506</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2022-04-02T12:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Spring4Shell Bug - yes another Log4J issue</title>
      <link>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50432#M515</link>
      <description>&lt;P&gt;HI All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a follow up to to my original piece - it appears the number of systems affected is far greater than organisations anticipated.&amp;nbsp;&amp;nbsp; Some sleepless nights for many.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.darkreading.com/application-security/vulnerable-spring-framework-instances-estimated-at-possibly-millions" target="_blank"&gt;https://www.darkreading.com/application-security/vulnerable-spring-framework-instances-estimated-at-possibly-millions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:11:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Spring4Shell-Bug-yes-another-Log4J-issue/m-p/50432#M515</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-04-07T06:11:38Z</dc:date>
    </item>
  </channel>
</rss>

