Once they're known. I suppose nexus firewall let log4j pass.
Once they're known. I suppose nexus firewall let log4j pass.
1. https://github.com/ossillate-inc/packj 2. https://github.com/ossillate-inc/packj-github-action
Isn't that how life works? Unknown unknowns? :-)
> I suppose nexus firewall let log4j pass.
It should be reasonable to assume that a product dedicated to something will, on average, do this job better/faster than a random developer, though. Since that's their job.
So Nexus Firewall presumably blocks these vulnerabilities faster than the average app/system developer notices them. There's value in reducing the delta between the vulnerability exploit day and an entire ecosystem being patched/fixed.
Once log4shell was discovered it was trivial to eliminate it from the organisation. We knew exactly what projects were using it and updated them accordingly. Access logs showed us that it was no longer used and we delete it.