Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

log4j2-core-2.17.0 is marked as potential vulnerable #151

Closed
ChKemper opened this issue Dec 19, 2021 · 1 comment
Closed

log4j2-core-2.17.0 is marked as potential vulnerable #151

ChKemper opened this issue Dec 19, 2021 · 1 comment
Assignees
Labels
bug Something isn't working patch released

Comments

@ChKemper
Copy link
Contributor

Hi,

after applying the latest fixes the log4j-core-2.17.0.jar is marked as potentially vulnerable:

[?] Found CVE-2021-44228 (log4j 2.x) vulnerability in /Users/xgadkem/Downloads/log4j/log4j-core-2.17.0.jar, log4j N/A - potentially vulnerable.

I think the bug is related in class Detector:220 and Detector:176.
When reading the pom.properties of 2.17 there is no version given back. So in line 220 the JAR is marked as mitigrated (because the JndiLookup class existes).

I've made my test with the attatched JAR.
log4j-core-2.17.0.jar.zip

@ChKemper ChKemper changed the title log4j2-core-2.17.0 is marked as potential vulnarable log4j2-core-2.17.0 is marked as potential vulnerable Dec 19, 2021
@xeraph xeraph added the bug Something isn't working label Dec 19, 2021
@xeraph xeraph closed this as completed in 1a49d24 Dec 19, 2021
xeraph added a commit that referenced this issue Dec 19, 2021
@xeraph
Copy link
Contributor

xeraph commented Dec 19, 2021

@ChKemper Thank you for your patch PR again. :D

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working patch released
Projects
None yet
Development

No branches or pull requests

2 participants