Log4j 2.17.0 - CVE-2021-45105 #45
yunzheng
announced in
Announcements
Replies: 2 comments
-
Note that this update is only in the source repository yet, hope to push out a new release today. If you cannot wait, get auto generated binaries from here: https://github.com/fox-it/log4j-finder/actions |
Beta Was this translation helpful? Give feedback.
0 replies
-
Hi Thanks for the amazing project. I have noted that 2.17.0 is listed as good as per your last updated version. However it has been superseded by 2.17.1 which is now deemed the only GOOD version. Any plans to update the code? Thank you Shidoshi |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
A new Log4j version has been released that fixes an Infinite recursion issue in lookup evalution.
Source:
I just pushed changes to log4j-finder (see #43) to mark
log4j 2.17.0
as the onlyGOOD
version, everything older than 2.17.0 is now marked asVULNERABLE
.Beta Was this translation helpful? Give feedback.
All reactions