{"id":13844150,"url":"https://github.com/authomize/log4j-log4shell-affected","last_synced_at":"2025-07-11T22:30:50.149Z","repository":{"id":45348211,"uuid":"437562080","full_name":"authomize/log4j-log4shell-affected","owner":"authomize","description":"Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability ","archived":false,"fork":false,"pushed_at":"2021-12-19T07:40:25.000Z","size":98,"stargazers_count":53,"open_issues_count":0,"forks_count":8,"subscribers_count":23,"default_branch":"main","last_synced_at":"2024-02-11T21:17:57.999Z","etag":null,"topics":["cve-2021-44228","log4j","log4j-rce"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/authomize.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-12-12T14:05:05.000Z","updated_at":"2024-02-11T21:17:58.000Z","dependencies_parsed_at":"2022-08-29T20:31:11.846Z","dependency_job_id":null,"html_url":"https://github.com/authomize/log4j-log4shell-affected","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/authomize%2Flog4j-log4shell-affected","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/authomize%2Flog4j-log4shell-affected/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/authomize%2Flog4j-log4shell-affected/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/authomize%2Flog4j-log4shell-affected/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/authomize","download_url":"https://codeload.github.com/authomize/log4j-log4shell-affected/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225763257,"owners_count":17520426,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cve-2021-44228","log4j","log4j-rce"],"created_at":"2024-08-04T17:02:35.929Z","updated_at":"2024-11-21T16:30:39.849Z","avatar_url":"https://github.com/authomize.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# log4j-log4shell-affected\nLists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE) for security responders. \n\nWe believe it is important to classify the vendors and products between:\n1. Internal risk - what you need to patch first to remove risk internally\n2. External risk - all third/fourth-party vendors that have custody of your data that might've been hacked that you will need to monitor and tackle once you're done patching\n\n### Here are the lists:\n\n#### [External Risk - Affected Apps](https://github.com/authomize/log4j-log4shell-affected/blob/master/affected_apps.md)\n\ni.e. all vendors you should worry about if you have data in their environemnt or if they access to your environment\n\n#### [Internal Risk - Affected Components](https://github.com/authomize/log4j-log4shell-affected/blob/master/affected_components.md)\n\ni.e. software components you might have used in building your products that you should worry if they cause you to be vulnerable \n \n\n## Other useful resources\n### Lists\n\n[Artifacts using log4j](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core)\n\n[Compromised apps with confirmation](https://github.com/YfryTchsGD/Log4jAttackSurface)\n\n[List of responses from various vendors, some affected and some not](https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592)\n\n[Official list maintained by CISA - US Govt](https://github.com/cisagov/log4j-affected-db)\n\n[Official list maintained by NCSC - NL govt, high update frequency](https://github.com/NCSC-NL/log4shell/tree/main/software)\n\n\n### Guides how to repsond\n\n[A fast and simple guide on what to do to respond to the log4j incident](https://www.authomize.com/blog/authomizes-response-and-mitigation-guide-to-the-log4shell-vulnerability/)\n\n[General incident response guide in case you discover a 3rd party vendor of yours got hacked](https://resources.panorays.com/hubfs/assets/The_Third-Party_Incident_Response_Playbook.pdf)\n\n\n## Contributing\nWe are happy to recieve contributions from the community. \nContribution guidelines:\n- Please make a PR editing the raw CSV files. \n- Please be sure to include a reference source for each added row (claims without a validated link for source of claim will not be accepted)\n\n\n## About this repo\nThis repo is maintained to simplify response for enterprises and organizations by separating between:\n1. Internal risk - Software components you need to search for and patch in your products / internal environment\n2. External risk - Third and fourth-party vendors/apps who might've been affected and you should to monitor if your data is in their custody\n\nThis list is a community project open for everyone to contribute to and is curated by:\n![Authomize Logo](https://www.authomize.com/wp-content/uploads/2021/12/github-banner-authomize.png)\n\n\n## Our favorite description of the situation\n![Meme](https://user-images.githubusercontent.com/57227377/145719037-d8fe4303-7d50-41ea-919f-1e7f525f8680.png)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fauthomize%2Flog4j-log4shell-affected","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fauthomize%2Flog4j-log4shell-affected","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fauthomize%2Flog4j-log4shell-affected/lists"}