mergebase / log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC
Other
638 stars 98 forks source link

Add explanation of _OLD_ in README.md #27

Closed Nitschi closed 2 years ago

Nitschi commented 2 years ago

Hello,

A bunch of my programs give results such as

C:\Users\username\AppData\Local\JetBrains\Toolbox\apps\CLion\ch-0\201.7223.86\lib\log4j.jar contains Log4J-1.x   <= 1.2.17 _OLD_ :-|

I found this issue, but it's not yet documented.

Thank you for the helpful tool! Alex

juliusmusseau commented 2 years ago

Done! (Documented now!)