# Log4j
**Domain:** Software Infrastructure / Cybersecurity / Java
**Doc Type:** Software and Incident Node
**Maturity:** Canonical
## Definition
**Apache Log4j** is a widely used Java logging library. The critical Log4Shell vulnerability disclosed in December 2021 allowed remote code execution in vulnerable configurations and exposed the risks created by deeply embedded software dependencies.
## Infrastructure Context
The vulnerability appeared across a vast range of enterprise products and services, making inventory, patching and dependency discovery central parts of response.
## See Also
[[wiki/Supply Chain Compromise|Supply Chain Compromise]], [[wiki/Attack Surface|Attack Surface]], [[wiki/Incident Response|Incident Response]]