# The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant

DevFeed: [The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant](<https://devfeed.tech/articles/the-persistent-threat-why-major-vulnerabilities-like-log4shell-and-spring4shell-remain-significant-8006.md>)

Original publisher: [Read original article](<https://snyk.io/blog/log4shell-spring4shell-threat/>)

Author: Brian Vermeer

Published: 2024-08-29T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [log4j](<https://devfeed.tech/topics/log4j.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Spring Framework](<https://devfeed.tech/topics/spring-framework.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [java](<https://devfeed.tech/tags/java.md>), [log4j](<https://devfeed.tech/tags/log4j.md>), [logging](<https://devfeed.tech/tags/logging.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [spring-framework](<https://devfeed.tech/tags/spring-framework.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article examines the continued use of vulnerable Log4j and Spring Framework versions in software projects. It explains how Log4Shell could enable malicious code execution and cites scan data indicating that 21% of companies with production code scanning still had projects vulnerable to Log4Shell.

## Source excerpt

Read on to learn about the danger of the continued use of vulnerable Log4j and Spring Framework versions in many projects.