I have no hot takes about the recent log4j2 vulnerability.
It just was a lot of work to update all the container images involved in a microservices architecture.
This is one aspect of microservices that I never really considered before this happened.
Meanwhile, maintainers of monolithic Java applications and those that used the OS dependency didn't have as much work to do.
@njoseph_1 such are the shortcomings of static linking
Nevermind, I'm too tired.
Didn't realize the 2 was referring to the log4j version.
@Shamar @njoseph_1
Yes, but not all vulns are caused by dynamic linking. However all of them are fixed by updating the buggy code. If that requires rebuilding every binary (or a fat jar, or a docker image - all equivalents of a binary on different levels of abstraction), it makes the process slower and more laborious.