logpresso / CVE-2021-44228-Scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
Apache License 2.0
851 stars 174 forks source link

Add scanning for log4j 1.2 CVE-2021-4104 #98

Closed bilodeauj closed 2 years ago

bilodeauj commented 2 years ago

I've been made aware that according to CVE-2021-4104 that older versions of log4j 1.2 have a similar vulnerability to CVE-2021-44228. Would it be possible to add detection of those to the scanner as well?

xeraph commented 2 years ago

There are so many requests about log4j 1.x detection. I will address this issue in the next release.

ChKemper commented 2 years ago

https://github.com/logpresso/CVE-2021-44228-Scanner/pull/105