Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
log4j-vuln-demo — Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228) | Kitploit
Tools/GitHubGitHub/aaronm-sysdig/log4j-vuln-demo
Vulnerability ScannersVulnerability AnalysisCloud SecurityDevSecOpsSupply Chain SecurityLearning & Education
GitHubaaronm-sysdig/log4j-vuln-demo

log4j-vuln-demo

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

View Repository
3 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

log4j-vuln-demo

Intentionally vulnerable demo image for Sysdig CNAPP scanning and remediation testing.

Contains Log4j 2.14.1 — vulnerable to CVE-2021-44228 (Log4Shell, CVSS 10.0 Critical).

Purpose

This repo exists to demonstrate Sysdig's end-to-end CNAPP workflow:

  1. /sysdig-investigate — surfaces the vulnerable image and ranks it for remediation
  2. /sysdig-remediate — resolves a safe fix version (2.15.0+) and opens a PR

Fix

Bump log4j-core and log4j-api to 2.17.1 or later in pom.xml.

Image

Use a proper version # so you can then bump it to 1.0.1 or something

root@kitploit:~
ghcr.io/aaronm-sysdig/log4j-vuln-demo:1.0.0
Download Tool