trustedsec / ptf

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
5.09k stars 1.23k forks source link

zaproxy contains log4j exploit code #599

Open BustedSec opened 1 year ago

BustedSec commented 1 year ago

2022-09-20 06_23_49-Window The version of ZAP installed is behind the master branch that addressed this

References: https://www.blumira.com/analysis-log4shell-local-trigger/ https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/

https://github.com/zaproxy/zaproxy/pull/6979. https://github.com/zaproxy/zaproxy/issues/6980

Unsure what magic was done, image but the magic needs updating to the most recent URL to pull a newer version via wget.