The Software Composition Analysis leader now offers a remediation preset for WhiteSource Renovate and Enterprise, enabling users to identify and fix the Log4j vulnerability from hundreds of downstream dependent packages of Log4j.
TEL AVIV AND BOSTON – January 4, 2022 – WhiteSource, a leader in open source security and management, today announced that a Log4j remediation preset is now included in both its commercial product and free GitHub developer tool. This preset allows enterprises to find and automatically fix both direct and indirect Log4j dependencies, which is something that no other security vendor is currently providing. In addition, a new online resource center has been made available by the company, to provide Log4j remediation and secure coding best practices.
Since the Log4Shell vulnerability was first published by the national vulnerability database (NVD) on Dec 12th, 2021, two additional vulnerabilities were found in the popular Java logging framework, Log4j. Our research shows that Log4j has been used in over 52% of applications used across top 2000 organizations in the software development industry.
While additional vulnerabilities may still be found, the new versions of Log4j resolve all known vulnerabilities. However, many packages in the Maven and Gradle ecosystems use Log4j, so remediating it requires more than just upgrading Log4j in direct dependencies — it may also require upgrading multiple indirect dependencies. The new remediation preset by WhiteSource helps to address the challenge faced by security teams in updating indirect (transitive) dependencies.
“As news of new Log4j exploits emerge daily, it’s crucial for developers using Log4j to quickly and proactively update Log4j to a secure version,” said Rhys Arkins, Director of Product Management at WhiteSource. “WhiteSource Renovate combined with Merge Confidence helps developers support that strategy.”