Ross ROSS = Recommend OSS · open-source software intelligence for agents

Cybereason/Logout4Shell

Use Log4Shell vulnerability to vaccinate a victim server against Log4Shell observed · 2026-08-28

github.com/Cybereason/Logout4Shell · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1727
  • days_rel: n/a
  • days_push: 1716
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1692 stars · 106 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Java-based proof-of-concept tool by Cybereason that exploits the Log4Shell vulnerability (CVE-2021-44228) to 'vaccinate' a vulnerable server, setting formatMsgNoLookups to true and removing the JNDI Interpolator to block further exploitation. It supports Log4j versions 2.0 through 2.14.1 and is intended as an emergency mitigation when patching is not immediately possible.

Use cases

  • mitigate log4shell on a server i can't restart
  • emergency fix for cve-2021-44228 before patching
  • vaccinate a vulnerable log4j server remotely
  • disable jndi lookups in log4j without a restart
  • stop log4shell exploitation attempts on my java server

When to choose

  • you need an immediate stopgap mitigation for Log4Shell on servers you cannot immediately patch or restart
  • you are running Log4j 2.0-2.14.1 and need to disable JNDI lookups remotely

When to avoid

  • you can simply upgrade Log4j to 2.17.0 or later - patching is the proper fix
  • you need a supported, production-grade security tool rather than a proof of concept
  • your Log4j version is outside the 2.0-2.14.1 supported range

Facets

cli-tool · maturity maintenance

security vulnerability-scanning security backend developer-tools jvm cross-platform log4shell cve-2021-44228 mitigation vaccination proof-of-concept

1 source

Member repositories

RepositoryRoleHealth v2
Cybereason/Logout4Shellmain32

For agents

markdown · JSON · MCP: product_card(name="Cybereason/Logout4Shell")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem