SafeLog4j is an open-source tool that can detect and verify vulnerable Log4j applications and protect them.
This project comes after a 0-day exploit in the Java logging library, Log4j (version 2) was discovered on December 9. The vulnerability resulted in Remote Code Execution by logging a certain string.
SafeLog4j works inside an application, blocking the actual vulnerability from occurring. It does not rely on signatures and applications can safely log any data. It uses the instrumentation approach of Contrast Assess and Protect, but scoped to the single Log4j 2 CVE.