# Log4j **Domain:** Software Infrastructure / Cybersecurity / Java **Doc Type:** Software and Incident Node **Maturity:** Canonical ## Definition **Apache Log4j** is a widely used Java logging library. The critical Log4Shell vulnerability disclosed in December 2021 allowed remote code execution in vulnerable configurations and exposed the risks created by deeply embedded software dependencies. ## Infrastructure Context The vulnerability appeared across a vast range of enterprise products and services, making inventory, patching and dependency discovery central parts of response. ## See Also [[wiki/Supply Chain Compromise|Supply Chain Compromise]], [[wiki/Attack Surface|Attack Surface]], [[wiki/Incident Response|Incident Response]]