Uploaded image for project: 'Minecraft: Java Edition'
  1. Minecraft: Java Edition
  2. MC-247428

Log4Shell is (still) not fully patched.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • None
    • 1.18.1
    • None
    • OS: Windows 10 21H1
      Java Version: Java 17.0.1 (Bundled)
    • Unconfirmed
    • (Unassigned)

      According to https://github.com/advisories/GHSA-7rjr-3q55-vv33, the current workaround for Log4Shell is NOT sufficient.

      Note that previous mitigations involving configuration such as to set the system property log4j2.formatMsgNoLookups to true do NOT mitigate this specific vulnerability.

      This means that Minecraft is (potentially) still exploitable. Further research is needed if it just so happens to not be, but I recommend an upgrade to Log4J 2.17.1 wherever possible.

      (yes, I know this is already reported as MC-245918, but that has been closed as invalid)
      PS: Is the Legacy Launcher affected?

            Unassigned Unassigned
            FavoritoHJS FavoritoHJS
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: