Skip to main content
Naidu
New Member
July 10, 2025
Question

Possible lookup injection into Log4j messages.

  • July 10, 2025
  • 0 replies
  • 211 views

There is vulnerability find in Fortidevsec tool. We verified with developers, as they are saying there is no possible to inject in logger. Hence they are saying false positive. Is it possible to false positive? what are the things to verify in the code level?