Log4jscanner
github.com
github.com
I say this from weeks for this log4j ordeal.
this is the decision logic:
func (c *checker) bad() bool {
return (c.hasLookupClass && c.hasOldJndiManagerConstructor) || (c.hasLookupClass && c.seenJndiManagerClass && !c.isAtLeastTwoDotSixteen)
}
And most of the code I see is about walking the filesystem, unzipping jars, walking the files inside the jars.
Most codebases have this kind of plumbing all the time.
Like the other Google project, Bloaty McBloatface.
Theoretically, some particularly insane application could download and run a jar purely in memory without it ever touching the disk. That's so close to malware-like behavior that only the most insane legit programs would ever do that.
A Linux VPS running a Node app is unlikely to even have Java installed. It's a pretty big dependency and you couldn't miss it.
Also, is there a good command to run to reliably check if Java is installed on a system?
Yes! I frequently review any containers from the cloud I run. Load on isolated VM, start, cursory inspection at least. Then with images I'm happy with we keep them internally, until we need the upgrade.
/Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar
/System/Volumes/Data/Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar
Should I just delete them or is there a different mitigation? Apple needs to ship a patched Xcode version ASAP.
> Xcode contains a copy of the log4j library that has the CVE-2021-44228 security vulnerability. Xcode automatically downloads an updated version of this library and installs it into ~/Library/Caches/com.apple.amp.itmstransporter. When submitting apps to the App Store, Xcode uses the updated version of the library. (86390060)
[0] https://developer.apple.com/documentation/xcode-release-note...