DEV Community

Discussion on: Massive Log4j Java vulnerability: What it is & how to fix it?

Collapse
 
jimas13 profile image
jimas13 • Edited

I suggest you correct the "zero day vulnerability" definition, as the definition you have given it will confuse a lot of people. Basically, a zero day vulnerability is the time that the vulnerability goes public and no patch has been developed, which means that it's out there and ready to be exploited.
Here's the official:
"A zero-day (also known as 0-day) is a computer-software vulnerability either unknown to those who should be interested in its mitigation (including the vendor of the target software) or known and a patch has not been developed. Until the vulnerability is mitigated, hackers can exploit it to adversely affect programs, data, additional computers or a network.[1] An exploit directed at a zero-day is called a zero-day exploit, or zero-day attack."

Collapse
 
mukundmadhav profile image
Mukund Madhav

I wanted to simplify from the Wikipedia explaination. As essentially, zero day means that all systems are immediately prone to attack and patch should happen immediately.

Collapse
 
jimas13 profile image
jimas13

Ok mate, but the outcome is far away from the original.