Case Study Deskcasestudydesk.com
Enterprise Cloud InfrastructureSourced

Case Study: Nutanix remediated the Log4j vulnerability across its codebase in 4 days with Sourcegraph

Nutanix Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
Nutanix
Industry
Enterprise Cloud Infrastructure
Challenge
Nutanix needed to find and fix every Log4j instance across a large codebase, fast and completely.
Headline result
Full Log4j identification and remediation in days, with complete coverage

Key results

4 days
To deliver patches fully remediating Log4j
Across the full codebase
2 days
To identify every Log4j instance
5 min
To identify, fix and release the JMSAppender fix
100%
Confidence identifying every Log4j instance

The challenge

When the Log4j vulnerability was disclosed, Nutanix needed to locate every instance across its extensive codebase and remediate it quickly. The critical requirement was confidence that no vulnerable instance had been missed anywhere in the code.

The solution

Nutanix used Sourcegraph's code search to query its entire codebase and pinpoint every Log4j instance, then track patches to completion. Running a single search across all repositories replaced manual, repository-by-repository investigation.

It's nice when you can just run a report and say, 'Here it is,' or 'Here it isn't.' It's much better than having to say, 'Well, boss, I think we got it all.'

JK
Jon Kohler
Technical Director of Solution Engineering, Nutanix

The results, in context

Nutanix identified, fixed, and released a fix for the JMSAppender vulnerability in 5 minutes, identified every Log4j instance in 2 days, and delivered patches fully remediating the vulnerability in 4 days. The team reported 100% confidence that every instance had been found.

Products used

Sourcegraph SourcegraphSourcegraph Code Search