Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
log4shell-finder — أسرع ماسح لنظام الملفات لـ log4shell (CVE-2021-44228, CVE-2021-45046) وغيرها من الحالات الضعيفة (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) لمكتبة log4j. أداء ممتاز وبصمة ذاكرة منخفضة. | Kitploit
أدوات/GitHubGitHub/hynekpetrak/log4shell-finder
التحليل الثابتماسحات الثغرات الأمنيةتحليل الثغرات الأمنيةتحليل الكودأمن سلسلة التوريدسوء التكوين
GitHubhynekpetrak/log4shell-finder

log4shell-finder

أسرع ماسح لنظام الملفات لـ log4shell (CVE-2021-44228, CVE-2021-45046) وغيرها من الحالات الضعيفة (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) لمكتبة log4j. أداء ممتاز وبصمة ذاكرة منخفضة.

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
3913منذ 3 سنواتتمت المراجعة من قبل Kitploit

log4shell-finder - أسرع ماسح لنظام الملفات للبحث عن مثيلات log4j

نسخة Python من https://github.com/mergebase/log4j-detector - log4j-detector حقوق النشر (C) 2021 شركة Mergebase Software Inc. https://mergebase.com/ مرخص بموجب GPLv3.

الدافع لتحويله إلى Python كان تحسين الأداء وتقليل استهلاك الذاكرة وزيادة وضوح الكود. انظر القسم أدناه حول مقارنة الأداء.

ويبدو أن هذه أسرع أداة مسح بأقل متطلبات ذاكرة

تحدد إصدارات log4j (1.x) و reload4j (1.2.18+) و log4j-core (2.x) على نظام الملفات لديك المعرضة لثغرات CVE-2021-44228 و CVE-2021-45046 وغيرها الكثير - انظر الجدول أدناه. يمكنها العثور على مثيلات مدمجة في تطبيقات أكبر بعدة طبقات عمقاً. تعمل على Linux و Windows و Mac أو أي مكان آخر يعمل عليه Python 3.8+.

يمكنها اكتشاف log4j بشكل صحيح داخل ملفات executable spring-boot jars/wars، والتبعيات المخلوطة في uber jars، و shaded jars، وحتى الملفات jar المفكوكة جالسة غير مضغوطة على نظام الملفات (المعروفة باسم *.class).
يمكنها أيضاً التعامل مع ملفات shaded class - امتدادات .esclazz (elastic) و .classdata (Azure).

ملحقات أرشيفات Java التي يتم البحث فيها: .zip، .jar، .war، .ear، .aar، .jpi، .hpi، .rar، .nar، .wab، .eba، .ejb، .sar، .apk، .par، .kar

الثغرات التي تم اكتشافها

يتم الإبلاغ عن كل مثيل مع قائمة مناسبة من CVEs. لكل CVE، يتم تحليل ملف مكتبة log4j لمعرفة ما إذا كان قد تم تطبيق الحلول البديلة الموصى بها (مثل إزالة JndiLookup.class أو JMSAppender.class) وفي هذه الحالة يعتبر غير معرض للخطر. يتم الإبلاغ عن الحالة STRANGE للأرشيفات التي تحتوي على ملفات pom.properties الخاصة بـ log4j-core، ولكن بدون فئات bytecode الفعلية، وعادةً ما تكون هذه حزم مصدرية ويمكن تجاهلها.

تحذير ميزة --fix تجريبية، استخدمها على مسؤوليتك الخاصة، تأكد من عمل نسخة احتياطية من ملفات jar الخاصة بك قبل استخدامها.

الوسيطة --fix تحاول إعادة تسمية مثيلات JndiLookup.class إلى JndiLookup.vulne، وبالتالي تمنع تحميل الفئة. داخل أرشيفات Java يتم ذلك عبر إعادة التسمية في المكان، ولا يتطلب إعادة ضغط الأرشيف وسريع جداً.

الملفات الثنائية متاحة لـ Linux 64 بت، MS Windows 64 بت و 32 بت - انظر Releases

أقل إصدار Python مدعوم هو 3.8. وفقاً لاختباراتي، لا يمكن لتنفيذ zip في Python 3.6 فتح العديد من ملفات .jar من بيانات الاختبار الخاصة بي.

الأداء

تم تحسين log4shell finder للأداء واستهلاك منخفض للذاكرة.

تم التحديث في 23.1.2022، تم قياس الأداء على دليل يحتوي على 26237 ملفاً في 2005 مجلداً.

وقت التشغيل انخفض إلى النصف، استهلاك الذاكرة إلى 2/3، قراءات نظام الملفات بنسبة 90% على الأقل

log4shell-finder (هذه الأداة)

root@kitploit:~
Command being timed: "./test_log4shell.py /home/hynek/war/ --exclude-dirs /mnt --same-fs"
User time (seconds): 17.68
System time (seconds): 1.20
Percent of CPU this job got: 127%
Elapsed (wall clock) time (h:mm:ss or m:ss): 0:14.47
Maximum resident set size (kbytes): 64144
File system inputs: 114424

log4j-finder (https://github.com/fox-it/log4j-finder)

root@kitploit:~
Command being timed: "./log4j-finder.py /home/hynek/war/"
User time (seconds): 23.59
System time (seconds): 1.09
Percent of CPU this job got: 99%
Elapsed (wall clock) time (h:mm:ss or m:ss): 0:26.18
Maximum resident set size (kbytes): 38604
File system inputs: 142824

log4j-detector (https://github.com/mergebase/log4j-detector)

root@kitploit:~
Command being timed: "java -jar log4j-detector-latest.jar /home/hynek/war"
User time (seconds): 30.56
System time (seconds): 1.39
Percent of CPU this job got: 113%
Elapsed (wall clock) time (h:mm:ss or m:ss): 0:28.26
Maximum resident set size (kbytes): 214116
File system inputs: 14416

log4j2-scan (https://github.com/logpresso/CVE-2021-44228-Scanner)

root@kitploit:~
Command being timed: "./log4j2-scan /home/hynek/war --scan-log4j1 --scan-zip"
User time (seconds): 52.05
System time (seconds): 25.32
Percent of CPU this job got: 88%
Elapsed (wall clock) time (h:mm:ss or m:ss): 1:27.86
Maximum resident set size (kbytes): 593080
File system inputs: 215416

سجل التغييرات

الإصدار 1.22-20220222

  • تمت الإضافة: قراءة إصدار المكتبة واسمها (log4j، log4j-core، reload4j) من MANIFEST.MF وكذلك من pom.properties
  • تحسينات في الأداء بنسبة 15% إضافية
  • تمت الإضافة: الكشف التلقائي عن جميع الأقراص المحلية في mswin باستخدام المعامل all
  • تمت الإضافة: --no-csv-header لتجاهل رأس csv للسماح بدمج النتائج من عدة أجهزة بسهولة
  • تمت الإضافة: كشف CVE-2017-5645 (9.8)، CVE-2019-17571 (9.8)، CVE-2022-23307 (8.1)، CVE-2022-23305 (9.8)، CVE-2022-23305 (9.8)، CVE-2022-23302 (8.1)، تحسين كشف CVE-2017-5645
  • تمت الإضافة: معامل --threads لضبط عدد خيوط المسح يدوياً
  • تمت الإضافة: معامل --cvs-clean لكتابة سطر "CLEAN" إلى مخرجات csv في حالة عدم اكتشاف أي مكتبة log4j
  • تمت الإضافة: معامل --cvs-stats لكتابة سطر "STATS" إلى مخرجات csv مع وقت التشغيل بالثواني وعدد الملفات والمجلدات الممسوحة

الإصدار 1.21-20220109

  • إصلاح الخلل: أمر --fix في الإصدارين 1.19 و 1.20 قد يؤدي إلى إتلاف أرشيفات .jar.

للتغييرات السابقة انظر ملاحظات الإصدار

الاستخدام

قم إما بالتشغيل من مترجم Python أو استخدم الملفات الثنائية لنظامي Windows/Linux من مجلد dist.

احرص على تشغيله كمستخدم لديه صلاحية (قراءة على الأقل) لنظام الملفات بأكمله. يقوم log4shell-finder باجتياز المجلدات التي يمكنه الوصول إليها فقط، ولا يبلغ عن أخطاء رفض الصلاحية.

root@kitploit:~
PS C:\D\log4shell_finder> python3 .\test_log4shell.py --help
usage:  Type "test_log4shell.py --help" for more information
        On Windows "test_log4shell.py c:\ d:\"
        On Linux "test_log4shell.py /"

Searches file system for vulnerable log4j version.

positional arguments:
  folders               List of folders or files to scan. Use "-" to read list of files from stdin. On MS Windows use "all" to scan all local drives.

optional arguments:
  -h, --help            show this help message and exit
  --exclude-dirs DIR [DIR ...]
                        Exclude given directories from search.
  -s, --same-fs         Don't scan mounted volumens.
  -j [FILE], --json-out [FILE]
                        Save results to json file.
  -c [FILE], --csv-out [FILE]
                        Save results to csv file.
  --csv-clean           Add CLEAN status line in case no entries found
  --csv-stats           Add STATS line into csv output.
  --no-csv-header       Don't write CSV header to the output file.
  -f, --fix             Fix vulnerable by renaming JndiLookup.class into JndiLookup.vulne.
  --threads [THREADS]   Specify number of threads to use for parallel processing, default is 6.
  --file-log [LOGFILE]  Enable logging to log file, default is log4shell-finder.log.
  --progress [SEC]      Report progress every SEC seconds, default is 10 seconds.
  --no-errors           Suppress printing of file system errors.
  --strange             Report also strange occurences with pom.properties without binary classes (e.g. source or test packages)
  -d, --debug           Increase verbosity, mainly for debugging purposes.
  -v, --version         show program's version number and exit

لا يتطلب أي مكتبات Python إضافية.

تجميع الملفات الثنائية

تم إنتاج الملفات الثنائية باستخدام:

root@kitploit:~
pip install pyinstaller
pyinstaller -F ./test_log4shell.py

إذا كنت ترغب في بناء إصدار 32 بت، قم بتثبيت مترجم Python 32 بت، وقم بتثبيت pyinstaller باستخدام:

root@kitploit:~
C:\Users\User\AppData\Local\Programs\Python\Python38-32\python.exe -m pip install pyinstaller

ثم:

root@kitploit:~
 C:\Users\User\AppData\Local\Programs\Python\Python38-32\Scripts\pyinstaller.exe -n test_log4shell-mswin32 -F test_log4shell.py 

مثال على التنفيذ

على Linux يمكنك التشغيل كالتالي:

root@kitploit:~
python3 ./test_log4shell.py / /opt --same-fs --no-errors

لـ MS Windows:

root@kitploit:~
python3 .\test_log4shell.py c:\ d:\ --same-fs --no-errors

على MS Windows:

تأكد من تثبيت pywin32، مثلاً عبر pip install pywin32

root@kitploit:~
PS C:\D\log4shell_finder> python3 .\test_log4shell.py c:\ --same-fs --no-errors

 8                  .8         8             8 8        d'b  o            8
 8                 d'8         8             8 8        8                 8
 8 .oPYo. .oPYo.  d' 8  .oPYo. 8oPYo. .oPYo. 8 8       o8P  o8 odYo. .oPYo8 .oPYo. oPYo.
 8 8    8 8    8 Pooooo Yb..   8    8 8oooo8 8 8        8    8 8' `8 8    8 8oooo8 8  `'
 8 8    8 8    8     8    'Yb. 8    8 8.     8 8        8    8 8   8 8    8 8.     8
 8 `YooP' `YooP8     8  `YooP' 8    8 `Yooo' 8 8        8    8 8   8 `YooP' `Yooo' 8
 ..:.....::....8 ::::..::.....:..:::..:.....:....:::::::..:::....::..:.....::.....:..::::
 :::::::::::ooP'.:::::::::::::::::::::::::::::::::   Version 1.17-20220105   ::::::::::::
 :::::::::::...::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 Parameters: .\test_log4shell.py c:\ --same-fs --no-errors
 Host info: 'hostname': 'TESTHOST', 'fqdn': 'TESTHOST.example.com', 'ip': '10.0.0.1', 'system': 'Windows', 'release': '10', 'version': '10.0.19043', 'machine': 'AMD64', 'cpu': 'Intel64 Family 6 Model 142 Stepping 12, GenuineIntel'

[+] [CVE-2021-4104 (8.1)]  Package c:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar contains Log4J-1.2.17 <= 1.2.17, JMSAppender.class found
[+] [CVE-2021-44832 (6.6), CVE-2021-45046 (9.0), CVE-2021-45105 (5.9)]  Package c:\Program Files\OWASP\Zed Attack Proxy\lib\log4j-core-2.15.0.jar contains Log4J-2.15.0 == 2.15.0
[+] [CVE-2021-44228 (10.0), CVE-2021-44832 (6.6), CVE-2021-45046 (9.0), CVE-2021-45105 (5.9)]  Package c:\Users\testuser\Downloads\sqldeveloper-20.4.1.407.0006-x64.zip -> sqldeveloper/sqldeveloper/lib/log4j-core.jar contains Log4J-2.13.3 >= 2.10.0
[+] [CVE-2021-44228 (10.0), CVE-2021-44832 (6.6), CVE-2021-45046 (9.0), CVE-2021-45105 (5.9)]  Package c:\Users\testuser\Downloads\sqldeveloper-20.4.1.407.0006-x64\sqldeveloper\sqldeveloper\lib\log4j-core.jar contains Log4J-2.13.3 >= 2.10.0


 Scanned 1162924 files in 286638 folders.
   Found 1 instances vulnerable to CVE-2021-4104 (8.1)
   Found 2 instances vulnerable to CVE-2021-44228 (10.0)
   Found 3 instances vulnerable to CVE-2021-44832 (6.6)
   Found 3 instances vulnerable to CVE-2021-45046 (9.0)
   Found 3 instances vulnerable to CVE-2021-45105 (5.9)

مسح Kali، مع عرض التقدم كل ثانية واستبعاد مجلد zip-bomb:

root@kitploit:~
root@kali:/home/hynek/log4shell-finder# python3 test_log4shell.py / --same-fs --no-errors --progress 1  --exclude-dirs /usr/share/seclists/Payloads/Zip-Bombs/

 8                  .8         8             8 8        d'b  o            8
 8                 d'8         8             8 8        8                 8
 8 .oPYo. .oPYo.  d' 8  .oPYo. 8oPYo. .oPYo. 8 8       o8P  o8 odYo. .oPYo8 .oPYo. oPYo.
 8 8    8 8    8 Pooooo Yb..   8    8 8oooo8 8 8        8    8 8' `8 8    8 8oooo8 8  `'
 8 8    8 8    8     8    'Yb. 8    8 8.     8 8        8    8 8   8 8    8 8.     8
 8 `YooP' `YooP8     8  `YooP' 8    8 `Yooo' 8 8        8    8 8   8 `YooP' `Yooo' 8
 ..:.....::....8 ::::..::.....:..:::..:.....:....:::::::..:::....::..:.....::.....:..::::
 :::::::::::ooP'.:::::::::::::::::::::::::::::::::   Version 1.18-20220106   ::::::::::::
 :::::::::::...::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 Parameters: test_log4shell.py / --same-fs --no-errors --progress 1 --exclude-dirs /usr/share/seclists/Payloads/Zip-Bombs/
 Host info: 'hostname': 'kali', 'fqdn': 'kali', 'ip': '10.0.0.2', 'system': 'Linux', 'release': '5.14.0-kali4-amd64', 'version': '#1 SMP Debian 5.14.16-1kali1 (2021-11-05)', 'machine': 'x86_64', 'cpu': ''

Skipping mount point: /data
Skipping mount point: /home
Skipping mount point: /dev
Skipping mount point: /sys
[+] [CVE-2021-4104 (8.1)]  Package /usr/share/paros/paros.jar contains Log4J-1.x <= 1.2.17, JMSAppender.class found
 After 1 secs, scanned 119762 files in 4853 folders.
        Currently at: /usr/share/icons/hicolor/48x48/apps/kali-jd-gui.png
Skipping blaclisted folder: /usr/share/seclists/Payloads/Zip-Bombs
 After 2 secs, scanned 190067 files in 12980 folders.
        Currently at: /usr/share/plasma/desktoptheme/kali/metadata.desktop
[+] [CVE-2021-44228 (10.0), CVE-2021-44832 (6.6), CVE-2021-45046 (9.0), CVE-2021-45105 (5.9)]  Package /usr/share/jsql-injection/jsql-injection.jar contains Log4J-2.14.0 >= 2.10.0
 After 3 secs, scanned 221233 files in 17725 folders.
        Currently at: /usr/share/maltego/maltego-ui/modules/com-paterva-maltego-transform-finder.jar
[+] [CVE-2021-44228 (10.0), CVE-2021-44832 (6.6), CVE-2021-45046 (9.0), CVE-2021-45105 (5.9)]  Package /usr/share/zaproxy/lib/log4j-core-2.14.1.jar contains Log4J-2.14.1 >= 2.10.0
[+] [CVE-2021-4104 (8.1)]  Package /usr/share/javasnoop/lib/log4j-1.2.16.jar contains Log4J-1.2.16 <= 1.2.17, JMSAppender.class found
 After 7 secs, scanned 233394 files in 18705 folders.
        Currently at: /usr/share/images/desktop-base/login-background.svg
 After 8 secs, scanned 301417 files in 27952 folders.
        Currently at: /usr/lib/python3/dist-packages/faraday_plugins/plugins/repo/dirb/plugin.py
 After 9 secs, scanned 342342 files in 34421 folders.
        Currently at: /usr/lib/jvm/java-8-openjdk-amd64/jre/lib/jexec
Skipping mount point: /run
Skipping mount point: /proc


 Scanned 379253 files in 37742 folders in 9.9 seconds.
   Found 2 instances vulnerable to CVE-2021-4104 (8.1)
   Found 2 instances vulnerable to CVE-2021-44228 (10.0)
   Found 2 instances vulnerable to CVE-2021-44832 (6.6)
   Found 2 instances vulnerable to CVE-2021-45046 (9.0)
   Found 2 instances vulnerable to CVE-2021-45105 (5.9)

مخرجات JSON

يحتوي المخرج إلى json على جميع العناصر الموجودة بالإضافة إلى معلومات المضيف:

root@kitploit:~
{
  "hostname": "myserver",
  "fqdn": "myserver",
  "ip": "10.0.0.1",
  "system": "Linux",
  "release": "5.4.0-58-generic",
  "version": "#64-Ubuntu SMP Wed Dec 9 08:16:25 UTC 2020",
  "machine": "x86_64",
  "cpu": "x86_64",
  "cmdline": "./test_log4shell.py / --exclude-dirs /mnt --same-fs --csv-out --json-out",
  "starttime": "2021-12-22 07:07:54",
  "items": [
    {
      "container": "Package",
      "path": "/home/hynek/.m2/repository/org/apache/logging/log4j/log4j-core/2.14.1/log4j-core-2.14.1.jar",
      "status": "CVE_2021_44228",
      "message": "contains Log4J-2.14.1 >= 2.10.0",
      "pom_version": "2.14.1"
    },
    {
      "container": "Package",
      "path": "/home/hynek/.m2/repository/org/apache/logging/log4j/log4j-core/2.16.0/log4j-core-2.16.0.jar",
      "status": "NOTOKAY",
      "message": "contains Log4J-2.16.0 == 2.16.0",
      "pom_version": "2.16.0"
    },
    {
      "container": "Package",
      "path": "/home/hynek/.m2/repository/log4j/log4j/1.2.17/log4j-1.2.17.jar",
      "status": "CVE_2021_4104",
      "message": "contains Log4J-1.2.17 <= 1.2.17, JMSAppender.class found",
      "pom_version": "1.2.17"
    },
    {
      "container": "Package",
      "path": "/home/hynek/.m2/repository/log4j/log4j/1.2.12/log4j-1.2.12.jar",
      "status": "CVE_2021_4104",
      "message": "contains Log4J-1.x <= 1.2.17, JMSAppender.class found",
      "pom_version": "1.x"
    },
    {
      "container": "Package",
      "path": "/home/hynek/war/elastic-apm-java-aws-lambda-layer-1.28.1.zip:elastic-apm-agent-1.28.1.jar",
      "status": "MAYBESAFE",
      "message": "contains Log4J-2.12.1 <= 2.0-beta8 (JndiLookup.class not present)",
      "pom_version": "2.12.1"
    }
  ]
}

مخرجات CSV

تحتوي على الأعمدة التالية:

root@kitploit:~
"datetime","ver","ip","fqdn","OS","Release","arch","container","status","path","message","pom_version","product"
"2022-01-24 10:59:36","1.22pre-20220123","10.0.0.1","mylinux","Linux","5.4.0-58-generic","x86_64","Folder","CVE-2022-23302 (6.6), CVE-2022-23305 (8.1), CVE-2022-23307 (8.1)","/home/hynek/war.bak/reload4j/reload4j-1.2.18.0/org/apache/log4j","contains log4j-1.2.18.0","1.2.18.0","log4j"
"2022-01-24 10:59:36","1.22pre-20220123","10.0.0.1","mylinux","Linux","5.4.0-58-generic","x86_64","Package","OLDSAFE","/home/hynek/war.bak/reload4j/reload4j-1.2.18.2.jar","contains reload4j-1.2.18.2","1.2.18.2","reload4j"
"2022-01-24 10:59:36","1.22pre-20220123","10.0.0.1","mylinux","Linux","5.4.0-58-generic","x86_64","Package","OLDSAFE","/home/hynek/war.bak/reload4j/reload4j-1.2.18.1.jar","contains reload4j-1.2.18.1","1.2.18.1","reload4j"
"2022-01-24 10:59:36","1.22pre-20220123","10.0.0.1","mylinux","Linux","5.4.0-58-generic","x86_64","Package","CVE-2019-17571 (9.8), CVE-2021-4104 (7.5), CVE-2022-23302 (6.6), CVE-2022-23305 (8.1), CVE-2022-23307 (8.1)","/home/hynek/war.bak/reload4j/log4j-1.2.17.jar","contains log4j-1.2.17","1.2.17","log4j"
"2022-01-24 10:59:36","1.22pre-20220123","10.0.0.1","mylinux","Linux","5.4.0-58-generic","x86_64","Package","CVE-2022-23302 (6.6), CVE-2022-23305 (8.1), CVE-2022-23307 (8.1)","/home/hynek/war.bak/reload4j/reload4j-1.2.18.0.jar","contains log4j-1.2.18.0","1.2.18.0","log4j"
تنزيل الأداة
يتم الكشفCVECVSSv3الخطورةJavaالثغرة منمعرض للإصدارات إلىتم الإصلاح فيالمكتبة
نعمCVE-2021-4422810.0حرجة82.0-beta92.14.12.15.0log4jv2
نعمCVE-2017-56459.8حرجة72.0-alpha12.8.12.8.2log4jv2
نعمCVE-2019-175719.8حرجة1.2.01.2.17nofixlog4jv1
نعمCVE-2021-450469.0حرجة7/82.0-beta92.15.0 باستثناء 2.12.22.12.2/2.16.0log4jv2
نعمCVE-2022-233059.8حرجة1.2.01.2.17nofix / 1.2.18.1log4jv1, reload4j
نعمCVE-2022-233079.8حرجة1.2.01.2.17nofix / 1.2.18.1log4jv1, reload4j
نعمCVE-2022-233028.8عالية1.01.2.17nofix / 1.2.18.1log4jv1, reload4j
نعمCVE-2021-41047.5عالية-1.01.2.17nofixlog4jv1
نعمCVE-2021-448326.6متوسطة6/7/82.0-alpha72.17.0، باستثناء 2.3.2/2.12.42.3.2/2.12.4/2.17.1log4jv2
-CVE-2021-425506.6متوسطة-1.01.2.71.2.8logback
نعمCVE-2021-451055.9متوسطة6/7/82.0-beta92.16.0، باستثناء 2.12.32.3.1/2.12.3/2.17.0log4jv2
-CVE-2020-94883.7منخفضة7/82.0-alpha12.13.12.12.3/2.13.2log4jv2