Skip to content
DevMeme
3709 of 7590
Security Post #4048 · source on Telegram

Thought Log4Shell was done? Cue CVE-2021-45046 plot twist

Description

The meme is a two-column, two-row layout of the classic “What if you / But God said” pointing figure (the face is pixel-blurred). Left column: top frame shows the figure pointing at the viewer with the overlaid text "What if you"; bottom frame shows the same person pointing upward with the text "But god said". Right column replaces the usual heavenly imagery with incident text: the upper right white panel reads "wanted to have a pleasant week after patching log4shell" in bold black letters, while the lower right dark panel displays "CVE-2021-45046" in large white type followed by the smaller sentence "It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations." The juxtaposition pokes fun at December 2021’s security scramble where engineers patched Log4Shell (CVE-2021-44228) only to discover a follow-up vulnerability days later, illustrating the relentless cycle of dependency patching, on-call fatigue, and security firefighting

Comments

9
Anonymous ★ Top Pick Sprint goal: “remove log4j CVEs.” Reality: velocity measured in how many Docker layers we rebuild before the next advisory drops
  1. Anonymous ★ Top Pick

    Sprint goal: “remove log4j CVEs.” Reality: velocity measured in how many Docker layers we rebuild before the next advisory drops

  2. Anonymous

    The only thing worse than discovering a critical zero-day on Friday is realizing on Monday that your weekend patch was basically security theater with extra steps - welcome to the Log4j patch-a-thon where CVE-2021-45046 was the sequel nobody asked for but everyone got

  3. Anonymous

    Log4j 2.15.0: the only hotfix with its own CVE, its own hotfix, and its own support group meeting every December

  4. Anonymous

    The Log4Shell saga perfectly encapsulates the modern SRE experience: you finally finish emergency patching CVE-2021-44228 across your entire infrastructure at 3 AM, update your incident postmortem, and start to relax - only to discover that Apache released 2.15.0 with an incomplete fix, and now CVE-2021-45046 requires you to do it all over again. It's like playing whack-a-mole with CVEs, except the moles are in your production logging framework, and your pager won't stop going off. At least we all learned that 'certain non-default configurations' is security-speak for 'we'll see you again next week.'

  5. Anonymous

    2.15.0 fixed Log4Shell… except for “non‑default configurations” - aka every enterprise config I’ve ever inherited

  6. Anonymous

    Log4j 2.15.0: Because fully securing non-default configs is for the next release

  7. Anonymous

    After rolling Log4j 2.15.0 across 40 services, CVE‑2021‑45046 reminded us that immutability applies to data structures, not incident queues

  8. @cptnBoku 4y

    God seems to hate Java

  9. @Agent1378 4y

    Well even our math is incomplete, so no wonder some patch is too

Use J and K for navigation