SBN

Contrast vs the Log4J2 CVE – A demonstration

This week, we proved that we could find the vulnerability that caused CVE-2021-44228 and stop attacks against it, without updating versions or using a WAF. Here is a short demonstration from our founder Jeff Williams: 

 

Some key takeaways from Jeff’s video:

Contrast SCA identified that the application uses the vulnerable version of log4j. Our runtime context also allows you to identify which applications use JMSAppender, the specific class that can be exploited using this CVE. 

Contrast Protect defended the applications against the underlying vulnerability. This means, Contrast was protecting you against this vulnerability long before it was disclosed as a CVE this week.

Finally, Contrast Assess detects the underlying vulnerability in applications. This means, Contrast will find the next vulnerability like this one, before it becomes a disclosed CVE or major incident. 

 

*** This is a Security Bloggers Network syndicated blog from AppSec Observer authored by Mahesh Babu. Read the original post at: https://www.contrastsecurity.com/security-influencers/contrast-vs-the-log4j2-cve-a-demonstration

Secure Guardrails