Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log4j vuln with two packages #281

Closed
4NSIK1 opened this issue Apr 5, 2024 · 3 comments
Closed

Log4j vuln with two packages #281

4NSIK1 opened this issue Apr 5, 2024 · 3 comments

Comments

@4NSIK1
Copy link

4NSIK1 commented Apr 5, 2024

Two of the packages both include older version of log4j-core and are susceptible to CVE-2021-44228 (Log4Shell).

  1. android-project-creator.sls
  2. portex.sls

Could these be removed or patched?

@digitalsleuth
Copy link
Contributor

More than likely they can be updated. Android Project Creator version 1.5.2 addresses this vulnerability, as does 3.0.3 of Portex. Let us take a look at the latest versions and see how we can go about getting them updated.

Cheers!

@lennyzeltser
Copy link
Contributor

We now have the updated version of Portex on REMnux.

@lennyzeltser
Copy link
Contributor

We now have the updated version of Android Project Creator on REMnux.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants