Demo • Features • Requirements • Installation • Usage • Contributing • Contact
You can use this tool to scan for all JAR files affected by Apache Log4J vulnerability CVE-2021-44228 and patch them on the fly.
- Scan for the vulnerability within your system regardless of the naming convention of the library.
- Deep scan for the vulnerability within nested libraries, compressed and concatenated libraries.
- Creates a report of all Java ARchives (JAR), WAR, EAR, and AAR within your system or directory, the reports will contain the safe (for asset management) and vulnerable JARs.
- Blazing fast ⚡, scalable and easy to use, (a system with more than 20k JARs takes about 3 mins)
- Nothing, just grab the script that's suitable for your system.
git clone https://github.com/xsultan/log4jshield.git
cd log4jshield
chmod +x log4jshield.sh
- If you'd like to make it callable move the script to your
bin
folder:export PATH=$PATH:$(cd -)/log4jshield.sh
-
Navigate to your desired directory or go to your root path by typing
cd /
-
Then run the tool
./log4jshield.sh
This will start scanning for all the JARs, then it will generate a report which will be created in the same path you ran the tool at.
Contributions are what make the open source community such an amazing place to learn, inspire, and create. Any contributions you make are greatly appreciated.
If you have a suggestion that would make this better, please fork the repo and create a pull request. You can also simply open an issue with the tag "enhancement". Don't forget to give the project a star! Thanks again!
- Fork the Project
- Create your Feature Branch (
git checkout -b feature/AmazingFeature
) - Commit your Changes (
git commit -m 'Add some AmazingFeature'
) - Push to the Branch (
git push origin feature/AmazingFeature
) - Open a Pull Request