Skip to content

Impacted jars by Apache Log4j Tool : Zero Day in Ubiquitous Under Active Attack (CVE-2021-44228) ?? #46

Discussion options

You must be logged in to vote

Hello @Sanjay122021,

We are using following jar provided by you.

Could you please elaborate on this? We don't provide such JARs.

You can check the dependencies of the project using mvn dependency:tree -Dscope=compile.

org.owasp:csrfguard🫙4.1.2-SNAPSHOT

+- javax.servlet:servlet-api:jar:2.5:provided
+- org.apache.commons:commons-lang3:jar:3.12.0:compile
+- commons-io:commons-io:jar:2.8.0:compile
+- com.google.code.gson:gson:jar:2.8.6:compile
+- org.slf4j:slf4j-api:jar:1.7.31:compile

org.owasp:csrfguard-extension-session🫙4.1.2-SNAPSHOT

+- org.owasp:csrfguard:jar:4.1.2-SNAPSHOT:compile
|  +- org.apache.commons:commons-lang3:jar:3.12.0:compile
|  +- commons-io:commons-io:jar:2.8.0:compile
|…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by forgedhallpass
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #45 on December 14, 2021 15:15.