Skip to content

Log4j core 2.17.1 shows as vulnerable #16

@bdw429s

Description

@bdw429s

If I download the latest Log4j core jar file from maven
https://repo1.maven.org/maven2/org/lucee/log4j-core/2.17.1/log4j-core-2.17.1.jar

and scan it, I get this message:

Analysing log4j-core-2.17.1.jar
CVE-2021-44228 found in class file D:\Downloads\log4j-core-2.17.1\org\apache\logging\log4j\core\util\NetUtils.class

Is the latest jar still vulnerable or is the scanner wrong? I'm using the latest Log4JDetector-0.7.2-jar-with-dependencies.jar to scan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions