Log4j 2.17.x: Five Unpatched CVEs Now Resolved with NES for Apache Log4j 2
HeroDevs releases a drop-in replacement for Log4j 2.17.x patching two TLS hostname verification bypasses and three log pipeline vulnerabilities with no upstream fix available.