# Log4J Exploit Updates

### Explore this page to stay updated on the latest Log4j exploit developments, access critical fixes, and empower yourself with the knowledge to protect your digital assets.

## Log4J Overview

At the heart of the digital landscape, security is paramount. In the wake of the Log4j exploit, our commitment to safeguarding the online world has never been stronger. As the stewards of Maven Central, our teams are working around the clock to ensure that the world has reliable and fast access to the latest Log4shell fixes. In this digital age where data breaches, vulnerabilities, and malware are a fairly common occurrence, our mission is clear: to provide you with the tools and information needed to fortify your digital defenses. Explore insights from our [10th Annual Software Supply Chain Report](/content/state-of-the-software-supply-chain/introduction/index.html).

### Log4J Percent Monthly Central Downloads

Downloads of vulnerable versions of Log4J still greater than 10% nearly three years after fixes were available.

## Explore React2Shell Vulnerability

React2Shell has the capability to become the next Log4Shell. Explore everything you need to know about RCE vulnerabilities within React and how to mitigate your risk in our latest blog.

[Read Blog](/content/blog/react2shell-rce-vulnerabilities-require-immediate-attention/index.html)

## Latest Insights

**Blog Post**  
### [FTC warning in wake of Log4j: Secure your software supply chain](/content/blog/ftc-warning-in-wake-of-log4j/index.html)

**Blog Post**  
### [Protecting Your Development Environment: Lessons from Log4j and Beyond](/content/blog/protecting-your-development-environment-lessons-from-log4j-and-beyond/index.html)

**Blog Post**  
### [What is the Log4j exploit?](/content/blog/a-new-0-day-log4j-vulnerability-discovered-in-the-wild/index.html)

**Blog Post**  
### [How Large Organizations Can Easily Scan for Log4j Vulnerabilities](/content/blog/how-large-organizations-can-easily-scan-for-log4j-vulnerabilities/index.html)

**Blog Post**  
### [Log4j Exploits Are Now Being Used to Spread Dridex Banking Trojan](/content/blog/log4j-exploits-are-now-being-used-to-spread-dridex-banking-trojan/index.html)

**Blog Post**  
### [How Much Should the Federal Government Worry about Log4j?](/content/blog/how-much-should-the-federal-government-worry-about-log4j/index.html)

## Free Tools to Help You Now

### Sonatype Vulnerability Scanner  
Product a Software Bill of Materials and catalog all of the components in your application.

[Scan Now](/content/solutions/vulnerability-management-tools/index.html)

### OSS Index  
Detect publicly disclosed vulnerabilities contained within your project's dependencies.

[Get Started](https://ossindex.sonatype.org/)

## Sonatype Documentation & Research

- **CVE-2021-44228**  
  **CRITICAL**  
  Original log4j CVE that started it all. Impacts “org.apache.logging.log4j.log4j-core” versions 2.x only: <2.15.0 affected.

- **CVE-2021-4104**  
  **MODERATE**  
  Less severe variant of CVE-2021-44228 impacting **log4j 1.x only**.

- **CVE-2021-45046**  
  **HIGH**  
  DoS vulnerability impacting **log4j-core** version <=2.15.0 but not 2.16.0.

- **SONATYPE-2021-4517 AKA CVE-2021-42550**  
  **MODERATE**  
  Similar to CVE-2021-4104, but impacts “logback-classic,” and “logback-core.”

- **SONATYPE-2021-4560**  
  **HIGH**  
  Applies to log4j 2.x versions until and including 2.15.0. Fixed version to be on is 2.16.0.
