|
|
|
|
|
by kbart
1652 days ago
|
|
Fair enough, but that's more of how you package things - you can either have a separate class in Java inside your jar or you can have a standalone agent application (often also yet another Java application), but the attack surface doesn't change much. If log4j would be a standalone agent running on the same application server with this RCE vulnerability, the end result would be exactly the same. |
|
But sure, take this reasoning too far and you end up with micro service spaghetti, so some balance is needed.