Case Study: Nutanix remediated the Log4j vulnerability across its codebase in 4 days with Sourcegraph
Key results
The challenge
When the Log4j vulnerability was disclosed, Nutanix needed to locate every instance across its extensive codebase and remediate it quickly. The critical requirement was confidence that no vulnerable instance had been missed anywhere in the code.
The solution
Nutanix used Sourcegraph's code search to query its entire codebase and pinpoint every Log4j instance, then track patches to completion. Running a single search across all repositories replaced manual, repository-by-repository investigation.
“It's nice when you can just run a report and say, 'Here it is,' or 'Here it isn't.' It's much better than having to say, 'Well, boss, I think we got it all.'”
JKJon KohlerTechnical Director of Solution Engineering, Nutanix
The results, in context
Nutanix identified, fixed, and released a fix for the JMSAppender vulnerability in 5 minutes, identified every Log4j instance in 2 days, and delivered patches fully remediating the vulnerability in 4 days. The team reported 100% confidence that every instance had been found.