Thought Log4Shell was done? Cue CVE-2021-45046 plot twist
Description
The meme is a two-column, two-row layout of the classic “What if you / But God said” pointing figure (the face is pixel-blurred). Left column: top frame shows the figure pointing at the viewer with the overlaid text "What if you"; bottom frame shows the same person pointing upward with the text "But god said". Right column replaces the usual heavenly imagery with incident text: the upper right white panel reads "wanted to have a pleasant week after patching log4shell" in bold black letters, while the lower right dark panel displays "CVE-2021-45046" in large white type followed by the smaller sentence "It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations." The juxtaposition pokes fun at December 2021’s security scramble where engineers patched Log4Shell (CVE-2021-44228) only to discover a follow-up vulnerability days later, illustrating the relentless cycle of dependency patching, on-call fatigue, and security firefighting
Comments
9Comment deleted
Sprint goal: “remove log4j CVEs.” Reality: velocity measured in how many Docker layers we rebuild before the next advisory drops
The only thing worse than discovering a critical zero-day on Friday is realizing on Monday that your weekend patch was basically security theater with extra steps - welcome to the Log4j patch-a-thon where CVE-2021-45046 was the sequel nobody asked for but everyone got
Log4j 2.15.0: the only hotfix with its own CVE, its own hotfix, and its own support group meeting every December
The Log4Shell saga perfectly encapsulates the modern SRE experience: you finally finish emergency patching CVE-2021-44228 across your entire infrastructure at 3 AM, update your incident postmortem, and start to relax - only to discover that Apache released 2.15.0 with an incomplete fix, and now CVE-2021-45046 requires you to do it all over again. It's like playing whack-a-mole with CVEs, except the moles are in your production logging framework, and your pager won't stop going off. At least we all learned that 'certain non-default configurations' is security-speak for 'we'll see you again next week.'
2.15.0 fixed Log4Shell… except for “non‑default configurations” - aka every enterprise config I’ve ever inherited
Log4j 2.15.0: Because fully securing non-default configs is for the next release
After rolling Log4j 2.15.0 across 40 services, CVE‑2021‑45046 reminded us that immutability applies to data structures, not incident queues
God seems to hate Java Comment deleted
Well even our math is incomplete, so no wonder some patch is too Comment deleted