The Cybersecurity and Infrastructure Security Agency ( CISA ) has announced the release of a scanner to detect web services affected by two remote code execution vulnerabilities found in Apache Log4j . The vulnerabilities are officially known as CVE-2021-44228 and CVE-2021-45046 .
See also: NVIDIA: Reveals the products affected by the Log4j bug

“log4j-scanner is a project derived from scanners created by other members of the open-source community and is released by CISA’s Rapid Action Force team to help organizations identifypotentially vulnerable web services affected by log4j vulnerabilities,” the cybersecurity agency explains.
This scanner shares the same foundation as other similar tools and features an automated scanning framework for the CVE-2021-44228 flaw (also known as Log4Shell Log4j). The scanner was developed by cybersecurity company FullHunt.
The tool allows security teams to scan network hosts to see if they are exposed to Log4j vulnerabilities and detect any web application firewall (WAF) bypasses that could allow criminals to execute code.
See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan
CISA lists the capabilities of log4j – scanner:
- Support for URL lists.
- Fuzzing for more than 60 HTTP request headers (not just 3-4 headers like previous tools).
- Fuzzing for Fuzzing for HTTP POST Data parameters.
- Fuzzing for JSON data parameters.
- DNS callback support for vulnerability discovery and validation.
- WAF Bypass payloads.

Log4j bugs: CISA tries to help identify vulnerable web services
This is just one of the latest actions CISA has taken to help government and private organizations respond to ongoing attacks, which in this case are abusing these critical vulnerabilities in the Apache Log4j logging library.
See also: GoDeal24 Christmas Sale: FREE Windows 11 and 10 with Office product purchases
The organization is also participating in a joint advisory with other cybersecurity agencies around the world and U.S. federal agencies. This advisory includes guidance for addressing the CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105 Log4j vulnerabilities.
CISA urges all organizations to update their systems to block criminals' attempts to exploit vulnerabilities in Log4j.
On Friday, CISA ordered Federal Civilian Executive Branch agencies to patch their systems by December 23.
Source: Bleeping Computer
