-
Notifications
You must be signed in to change notification settings - Fork 174
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Additional output of secure log4j Versions #273
Comments
Printed versions of secure versions "Copyright © 2021 Atruvia AG <[email protected]>"
@OrbbQ3 Would you test v3.0.1 release? You can use |
I tested the new version and get following result:
Scanner was startet with following arguments: For example put the file Can you please take a look into this again? Thank you |
@xeraph I Like this option. It would be nice to have also an additional summary line like
|
Hi @OrbbQ3, I tested with the files provided at
and CSV: I tested with parameters |
Hi @ChKemper, yes, you have right, it works with following call: The only thing, that i have to comment is, that the cve number in report is null. In my opinion this should be an empty string. The run with the argument
@xeraph: In my opinion, working of this commandline switches should be synced or the switches Thank you |
Printed versions of secure versions - also in given Files Refactoring report creation "Copyright © 2021 Atruvia AG <[email protected]>"
Hi,
the current implementation does not output secure log4j versions (for example 2.17.1) to the output files (for example csv) and to the console. After investigation in the code, it seems, there are these code fragments in file Detector.java, that prevent this:
Is it possible to ouput this versions as not vulnerable too (for example with a additional command line switch)?
Background:
Output of not vulnerable versions is needed for build up a history in splunk.
Thank you
The text was updated successfully, but these errors were encountered: