mergebase / log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC
Other
638 stars 98 forks source link

Canonicalize --exclude paths so that it works in Windows #80

Open hokching opened 2 years ago

hokching commented 2 years ago
  1. Canonicalize paths in --exclude array
  2. Add para dump, mainly for troubleshooting in Windows (without this I will not be able to come out with the exclude argument below (see https://github.com/mergebase/log4j-detector/issues/62#issuecomment-1005549050): java -jar log4j-detector-2021.12.20.jar --verbose --exclude="[\"D:\\scan\\nf\\item\\ignore\", \"D:\\scan\\nf\\item\\ignore2\"]" d:\scan\nf