-
Hello all, I searched through the old posts for log4j fixes before this and believe this is a new find that our tenable instance hit on I initially believed this to be a false positive, but after pulling down the jar file and running a "Jar -tf | grep Jndi" I found the vulnerable lookup class in it. Not sure what this file is being used for, but would appreciate confirmation from the team before re-rolling this finding as a false positive. |
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Sep 12, 2023
Replies: 1 comment 7 replies
-
What is the output of the following?
|
Beta Was this translation helpful? Give feedback.
7 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
In that case, yes, cloud images do have a
/source
directory. This is a snapshot of the source code from all major third-party products included with Security Onion. However, no services actually run from there. You can safely remove that folder.