Skip to content

bump Log4j version to >2.17 #4917

@JasonBuckner

Description

@JasonBuckner

Role

I play vanilla & modded Minecraft on servers.

Suggestion

address this Apache Log4j Security Vulnerability

Benefit

Apache Log4j Security Vulnerabilities are frowny face emoji and I'd like to be able to Minecraft again.

This suggestion is unique

  • I have searched the issue tracker and did not find an issue describing my suggestion, especially not one that has been rejected.

You may use the editor below to elaborate further.

CVE-2021-44832 is a lovely vulnerability that impacts all versions of Log4j from 2.0-beta7 to 2.17.0, excluding 2.3.2 and 2.12.4.
See also #4349.

Personally, I'm running Java 8 (for REASONS) and am stuck with version 2.0-beta9-fixed of Log4j.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions