Hacker News new | ask | show | jobs
by PeekPoke 1534 days ago
That's a good technical write-up. I wonder how much of an issue this CVE will be compared to Log4Shell....
1 comments

Depends a lot on how many Spring apps out there have the prereqs to be vulnerable. The widespread nature of Log4Shell is what made it “worse” than other RCE vulns. I don’t have a sense of how many vulnerable instances of this one might be out there but the number could be enormous.