aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Software
  • Solutions

Critical Log4j Vulnerability Still Being Downloaded 40% Of The Time, Sonatype Research Reveals In New Resource Center

  • aster.cloud
  • December 25, 2021
  • 3 minute read

The Log4j open source component has been downloaded nearly five million times since a critical vulnerability was first discovered in it on December 10th. However, 40% of those downloads are still of the known critically vulnerable versions, according to new data released by Sonatype, the pioneer in intelligent and secure software supply chain automation.

As stewards of the Central Repository, the largest public repository of open source Java components, Sonatype has the unique ability to analyze patterns and practices relating to the consumption and utilization of millions of open source libraries, including Log4j.


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

Consumption data relating to Log4j has been compiled into a new Log4j Vulnerability Resource Center, a tool to track and publicise the latest findings and exploit updates around the vulnerability. Sonatype experts update the resource center multiple times each day to reveal how the attack is quickly mutating to infiltrate new corners of open source projects.

Data highlights include:

  • Percent “positivity rate” of vulnerable downloads versus safe downloads, showcasing how the problem is or isn’t improving
  • Hourly captures of download volumes of specific Log4j versions
  • Hourly updates on download percentages per version
  • Percent of vulnerable and non-vulnerable downloads by country since the vulnerability was discovered

“Log4j is one of most popular Java projects across Maven Central and is the standard logging framework of choice for most other Java open source components, found in 7,000 projects,” said Brian Fox, co-founder and CTO of Sonatype. “The good news is we have seen very rapid adoption of upgraded versions in most of the world. However, the data indicates this adoption is both not globally consistent, and not complete, leaving 40% of the ongoing downloads occurring on vulnerable versions, with some parts of the world still grabbing vulnerable versions up to 80% of the time.”

Read More  Adaptavist Offers Enterprise DevSecOps Solution With Sonatype Partnership

Free Resources to Stop the Spread of Log4Shell

Sonatype has shared a number of free resources for the community, including the ability to easily scan applications for the Log4Shell vulnerability for free, whether you’re an open source project maintainer,  developer, or security professional.

The company has open sourced its long-standing enterprise-grade Nexus Intelligence data for the Log4Shell vulnerability, accessible in Sonatype’s free online intelligence platform OSS Index ,its code analysis platform Sonatype Lift (free for open source projects), and third party tools that use OSS Index data, like OWASP Dependency Check. Open-source maintainers using the Central Repository can also generate a software bill of materials (SBOM) for all the releases they make available there.

Lastly, Sonatype offers an always free vulnerability scanner you can download or use online. Not only will it alert you to all direct vulnerable versions of Log4j in your repositories but Sonatype employs secondary expansion technology, to find those transitive dependencies. It also goes beyond scanning manifests, utilizing a patented Advanced Binary Fingerprinting to identify what’s actually in components, including partially modified instances of those components.

“Our priority is helping our community of open source users secure their tools and make software supply chains safer, period. As managers of the Central Repository, Sonatype has long made scanning and analysis tools available for free to the community, and we’re pleased to continue that commitment in our response to this historic vulnerability,” said Fox. “With the combination of transitive dependencies and the number of variants of Log4j vulnerabilities, developers face an incredibly difficult challenge. Helping with remediation efforts is imperative; our team is here for the community.”

Read More  Google Supports CSRB Call For Open Source Security Improvements In Wake Of Log4j Report

About Sonatype

Sonatype is the full-spectrum software supply chain automation company. We empower developers and security professionals with intelligent platform tools to innovate more securely at scale. Our platform addresses every element of an organization’s entire software development life cycle, including third-party open source code, first-party source code, infrastructure as code, and containerized code. We help organizations develop consistently high-quality, secure software which fully meets their business needs and those of their end-customers and partners. More than 2,000 organizations, including 70% of the Fortune 100, and 15 million software developers already rely on our tools and guidance to help them deliver and maintain exceptional and secure software.

Media contacts

Babel PR for Sonatype in the UK

[email protected]

Mission North for Sonatype in the US

[email protected]


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • Central Repository
  • Log4j
  • Log4j Vulnerability Resource Center
  • Sonatype
  • Sonatype Lift
You May Also Like
men with computer website information and chat bubbles vector illustration
View Post
  • Software
  • Software Engineering

What is an ISV (independent software vendor)?

  • August 27, 2025
aster-cloud-erp-bill_of_materials_2
View Post
  • Software
  • Software Engineering

What is an SBOM (software bill of materials)?

  • July 2, 2025
aster-cloud-sms-pexels-tim-samuel-6697306
View Post
  • Programming
  • Software

Send SMS texts with Amazon’s SNS simple notification service

  • July 1, 2025
aster-cloud-website-pexels-goumbik-574069
View Post
  • Programming
  • Software

Host a static website on AWS with Amazon S3 and Route 53

  • June 27, 2025
oracle-ibm
View Post
  • Solutions
  • Technology

Google Cloud and Philips Collaborate to Drive Consumer Marketing Innovation and Transform Digital Asset Management with AI

  • May 20, 2025
View Post
  • Software
  • Technology

Canonical Releases Ubuntu 25.04 Plucky Puffin

  • April 17, 2025
View Post
  • Software
  • Technology

IBM Accelerates Momentum in the as a Service Space with Growing Portfolio of Tools Simplifying Infrastructure Management

  • March 27, 2025
Vehicle manufacturing
View Post
  • Software

IBM Study: Vehicles Believed to be Software Defined and AI Powered by 2035

  • December 12, 2024

Stay Connected!
LATEST
  • 1
    Expectations vs. Reality: The AI We Thought We’d Have in 10 Years
    • June 19, 2026
  • digital-nomad-freelancer-worker-2151205464 2
    One paperwork problem – Get your Digital Nomad Visa employment documents fast from UK, EU or Singapore
    • June 16, 2026
  • 3
    Samsung Art Store Brings Art Basel to Homes Worldwide With New Curated Collection
    • June 15, 2026
  • 4
    You Do Not Need to Invest in the IPO of SpaceX, Anthropic, and OpenAI
    • June 10, 2026
  • 5
    The consequences of relying on AI for accurate news
    • June 10, 2026
  • 6
    Connecting AI agents with unstructured data using Google Cloud Storage MCP Servers
    • June 10, 2026
  • 7
    WWDC26: Apple unveils next generation of Apple Intelligence, Siri AI, powerful parental controls, and an expansive set of software improvements
    • June 8, 2026
  • 8
    IBM and Google Cloud Announce Strategic Partnership to Scale AI with Human Expertise and AI‑Powered Delivery
    • June 4, 2026
  • Data center 9
    Data Sovereignty in Spain. It’s Not Just About the Law, It’s About Efficiency
    • June 3, 2026
  • 10
    Ink vs Pixels. What you miss versus what you are actually missing.
    • June 1, 2026
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • 1
    Banks race to patch new cyber vulnerabilities, and other cybersecurity news
    • May 25, 2026
  • pope-leo-xiv-cq5dam-1500.844 2
    Pope Leo XIV to Publish First Encyclical on Artificial Intelligence and Human Dignity on 25 May
    • May 22, 2026
  • 3
    Portfolio to Clients, and is Strengthened by Ongoing Project Glasswing Work
    • May 20, 2026
  • reMarkable Paper Pure 4
    Everything The reMarkable Paper Pure Actually Does
    • May 14, 2026
  • 5
    Scaling cloud and AI: Microsoft Azure’s commitment to Europe’s digital future
    • May 11, 2026
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.