google / log4jscanner

A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
Apache License 2.0
1.57k stars 120 forks source link

jar: create temp file in same directory before rename #23

Closed ericchiang closed 2 years ago

ericchiang commented 2 years ago

Don't know a good, general way of testing this without root. So no tests for now.

Fixes https://github.com/google/log4jscanner/issues/18