experdb / eXperDB-Monitoring

eXperDB-Monitoring - open source project for postgresql monitoring
GNU General Public License v3.0
20 stars 12 forks source link

[CVE-2021-44832] log4j 보안취약점 업데이트 필요 #171

Open 20hyun opened 2 years ago

20hyun commented 2 years ago

Describe the bug

log4j 보안취약점 스캔을 통해 확인된 결과입니다. 조치필요여부 확인부탁드립니다.

> log4j2-scan.exe --scan-log4j1 ./eXperDB-Monitoring
Logpresso CVE-2021-44228 Vulnerability Scanner 2.7.1 (2022-01-02)
Scanning directory: ./eXperDB-Monitoring
[*] Found CVE-2021-44832 (log4j 2.x) vulnerability in C:\imsi\eXperDB-Monitoring\eXperDB_Server\eXperDB_Monitoring_Agent\lib\log4j-core-2.17.0.jar, log4j 2.17.0
[*] Found CVE-2021-44832 (log4j 2.x) vulnerability in C:\imsi\eXperDB-Monitoring\eXperDB_Server\eXperDB_Monitoring_Agent_Manager\lib\log4j-core-2.17.0.jar, log4j 2.17.0
prensgold commented 1 year ago

symantec gives an error for your application and automatically deletes it from the system.