It's not a maintainability nor exploitation. This is low programming culture and weak security understanding issue, which should be solved by technologies. Money wouldn't make bigbiz engineers to review their dependencies.
Log4j doesn't just blow a hole in your servers, it's reopening that can of worms: Is Big Biz exploiting open source?
theregister.com/2021/12/14/log…




