OWASP Top – The Log4j Edition
OWASP Top 10 2021 - the #log4j edition:
A1 log before auth
A2
A3 log string interpolation
A4 noone has time 4 threat modeling
A5 JNDI enabled by default
A6 unfunded open source maintainers
A7
A8
A9 y u no filter ur logs???
A10 sending requests to remote ldaps is fun
Goodluck everyone and happy Tuesday