Forum Discussion
Apache Log4j Detection Additional Improvements Summary:...
Awesome, this is great news! Once 156001 is updated this will replicate the version information of each log4j jar file to the other log4j 2.X plugins (such as 156183 & 156327) and prevent these findings from occurring from updated jars/modules that have been renamed to previous versions correct?
I have been trying to get DISA to submit these changes to you as some products (ex: Cameo Systems Modeler https://docs.nomagic.com/display/FAQ/CATIA+Magic+and+No+Magic+products+affected+by+Log4Shell+log4j+vulnerability+-+CVE-2021-44228) tell you to update to application versions with log4j 2.16.0 then replace and rename the files which currently cause the mentioned 2.X findings to reappear even though they are not truly present.
Thanks in advance for any clarification and further assistance.