We have released a public free tool for detecting vulnerable Log4J versions within any applications that are vulnerable. Available on GitHub here: https://github.com/mergebase/log4j-detector
We have also prepared a YouTube video that explains the vulnerability in detail, and shows how MergeBase can prevent attackers from exploiting this vulnerability in running unpatched production systems.
Stay on top of the real risk of open source at any time.
Avoid false positives and get sophisticated upgrade guidance based on risk, compatibility and popularity.
More on Continuous ProtectionDetect and defend against known-vulnerabilities at runtime. The only SCA to do so.
The quickest way to respond to an imminent threat like log4j with CVE-2021-44228.
More on Run-time ProtectionCodeGreen is an early-warning defence for your in-house development and integrates directly into GitHub and BitBucket
More on BitBucket and Github apps