Skip to content

Releases: logpresso/CVE-2021-44228-Scanner

1.2.5 Release

14 Dec 05:38
Compare
Choose a tag to compare

Fixed broken directory traversal on Windows (caused by symbolic link skipping), See #23 (comment)

1.2.4 Release

14 Dec 04:29
Compare
Choose a tag to compare
  • Skip /proc and /sys directories. See #25
  • Fixed infinite loop caused by symbolic link. See #25
  • Fixed backup failure in symbolic link scenario. See #23
    • Fixed version uses copy instead of rename to keep inode number.
    • Fixed version truncates original file to 0 and rewrite JAR file using backup file.

1.2.3 Release

13 Dec 15:16
Compare
Choose a tag to compare
  • Added --force-fix option for automation. See #14
  • Print error message if patch is failed. See #13
  • Support also Java EE .ear file. See #10

1.2.2 Release

13 Dec 05:49
Compare
Choose a tag to compare
  • Added --trace option for diagnose. See #9
  • Added WAR support. See #10

1.2.1 Release

13 Dec 03:35
Compare
Choose a tag to compare

Fixed vulnerability summary report. See #8

1.2.0 Release

12 Dec 20:02
b8013fe
Compare
Choose a tag to compare
  • Support nested jar detection and mitigation patch (spring fat jar). See #3
  • Fixed OOB caused by major.minor version format (e.g. 2.0). See #4
  • Fixed exception handling of user input. See #5

1.1.1 Release

12 Dec 13:15
06f3e1c
Compare
Choose a tag to compare

Fixed vulnerable version check. See #1

1.1.0 Release

11 Dec 19:21
Compare
Choose a tag to compare

Added --fix option to immediate mitigation patch. Use it at your own risk.

1.0.1 Release

11 Dec 13:28
Compare
Choose a tag to compare

Added mitigation check.

  • Check if org/apache/logging/log4j/core/lookup/JndiLookup.class is removed.
  • Added (mitigated) tag to message.

1.0.0 Release

11 Dec 11:38
Compare
Choose a tag to compare

First release