Download Latest Version Version 1.14.0 source code.tar.gz (1.6 MB)
Email in envelope

Get an email when there's a new version of OWASP Find Security Bugs

Home / version-1.12.0
Name Modified Size InfoDownloads / Week
Parent folder
findsecbugs-cli-1.12.0.zip 2022-04-11 11.6 MB
README.md 2022-04-11 4.0 kB
Version 1.12.0 - Preventing the next Log4Shell.tar.gz 2022-04-11 1.6 MB
Version 1.12.0 - Preventing the next Log4Shell.zip 2022-04-11 2.5 MB
Totals: 4 Items   15.7 MB 0

This release includes a lot of small fixes. See the auto-generated for the complete changes. From those, here are two notable improvements:

  • Supports for JDK 17
  • Important fixes regarding signatures' files (Bug with generic )

In late 2021, the library log4j version 2 was vulnerable to JDNI/LDAP "injection". The Log4j2 project has been using FSB (at least once). I later found out that we had a small signature issue that could have warned of the Context.lookup() method risks. [#670] for more info.


What's Changed

New Contributors

Full Changelog: https://github.com/find-sec-bugs/find-sec-bugs/compare/version-1.11.0...version-1.12.0

>md5sum findsecbugs-cli-1.12.0.zip
3b27a4374ac89146574a6318cfc53529 *findsecbugs-cli-1.12.0.zip

>sha1sum findsecbugs-cli-1.12.0.zip
cc382af0fae095afa7d41eb14d105fb909d8bc5b *findsecbugs-cli-1.12.0.zip
Source: README.md, updated 2022-04-11