Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
  • Latest log4j2-scan documented here: 2.6.3 (12/26/2021 AM)
  • Latest Log4j2 versions: 2.17.0 (Java 8), 2.12.3 (Java 7), and 2.3.1 (Java 6)
    Minimum log4j2 version that parches RCE vulnerabilities for Java 8 and later: 2.16
  • Apache Log4j vulnerabilities: https://logging.apache.org/log4j/2.x/security.html

For Windows Computers

  • Download the "Windows x64, zip" version of the log4j2 scanner from https://github.com/logpresso/CVE-2021-44228-Scanner
  • Open a command prompt as an administrator, change to the directory where you downloaded and extracted the log4j scanner, and run the following command:

...

...