All Day DevOps: Third of Log4j downloads still pull vulnerable version despite threat of supply chain attacks

Share:

Shutting the proverbial back door to your networks “cuts the risks [of attacks] down tremendously”, said application security engineer Sean Wright at Friday’s All Day DevOps.

The keynote speaker urged security teams to have “appropriate access controls in place” in order to protect themselves against a 742% rise in ‘next generation’ supply chain attacks, a threat that has mushroomed since the SolarWinds incident rocked the open source ecosystem in December 2020.

Among other techniques, attackers are leveraging typosquatting, dependancy confusion, malicious code injections, vulnerabilities within packages, protestware, and takeovers of package author accounts (the latter prompting package managers to implement multi-factor authentication (MFA)).

“Make sure that your servers are really well defined [in terms of] what and who they can speak to”, said Wright, who re-recorded his virtual keynote presentation after technical hiccups cut his live appearance short.

“Your servers should never, never ever have open outbound access”, Wright advised.

Many modern supply chain attacks “leverage the fact that many organizations do filter things coming in, but they never pay any attention to what’s going out”, added Wright.

Swimming upstream

The dramatic increase in the size of the open source ecosystem has persuaded attackers to diversify beyond attacking applications to targeting their upstream components too, he noted. If anything, Wright was surprised they did not do this sooner and at greater scale.

For context, his own research indicated that between 2015 and 2022 there had been trillions of download requests across various package managers, with Java downloads soaring 3,870%, JavaScript rising 13,900%, and .NET jumping 34,100%.

When a typical app has 20-30 dependencies, which themselves will often have 5-10 dependencies with something like 10,000 lines of code each, finding vulnerabilities is not so much a ‘needle in a haystack’ problem but a “needle in an open ocean” challenge, according to Wright.

Resources such as Google’s Open Source Insights are therefore invaluable. This “awesome” tool builds dependency graphs for open source packages, and annotates them with ownership, license, popularity, and other metadata.

Wright also recommended using Dependancy Track for a centralized view of your software bills of materials (SBOMs).

When a vulnerability surfaces, he advised security teams to pay attention to the vector more than the severity score, since the CVSS rating often changes as understanding of a bug deepens.

Purge your build system

The former software developer warned that, while package managers are quick to remove rogue packages from public repos, their use of caching means developers should “purge” their private repos and local build systems.

He praised a raft of recent initiatives around bolstering the software supply chain – SLSA, Sigstore Cosign, NIST guidance, and OSSF Security Scorecards – but despite these resources there remains much work to do.

After all, the critical Log4j bug showed that organizations had failed to heed the lesson offered by the Apache Struts bug that thrashed Equifax’s reputation in 2017 – “we’re finding 33% of downloads are still the vulnerable version”, he lamented.

“You wouldn’t typically allow any random stranger to commit code to your codebase,” Wright concluded. “But when we’re pulling down packages from random developers that’s exactly what we’re doing.”

All Day DevOps is a 24-hour software developer-focused conference. Presentations are still available to view on demand.

https://portswigger.net/daily-swig/all-day-devops-third-of-log4j-downloads-still-pull-vulnerable-version-despite-threat-of-supply-chain-attacks

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:01 am, Jul 9, 2025
weather icon 13°C
L: 11° | H: 15°
few clouds
Humidity: 74 %
Pressure: 1020 mb
Wind: 1 mph NW
Wind Gust: 1 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 15%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:54 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 15°°C 0.03 mm 3% 7 mph 74 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 8 mph 71 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 8 mph 62 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 63 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 70 % 1018 mb 0 mm/h
Today 4:00 am
weather icon
13° | 13°°C 0 mm 0% 2 mph 74 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
14° | 16°°C 0 mm 0% 3 mph 67 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
19° | 22°°C 0 mm 0% 4 mph 54 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 24°°C 0 mm 0% 6 mph 49 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0.03 mm 3% 7 mph 42 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 3 mph 43 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 22°°C 0 mm 0% 3 mph 57 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 3 mph 62 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,711.17
0.94%
Ethereum(ETH)
€2,222.59
3.08%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.97
2.62%
Solana(SOL)
€129.60
2.60%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.146407
3.09%
Shiba Inu(SHIB)
€0.000010
2.39%
Pepe(PEPE)
€0.000009
2.72%
Scroll to Top