Mojira Archive
MC-245102

Bypass of seucrity patch for JNDI injection

A server may send a malicious packet which contains a precontrolled string, and when a malformed packet is received, some details are printed out in the game log with level WARN.

This can lead to the same issue which was patched with INFO logging. One of the packets affected may be plugin channels.

Also, is there a better way to backport the fix, like a JVM argument instead of a sort of hacky log fix?

Invalid

Semisol

2021-12-10, 01:05 PM

2021-12-11, 12:59 AM

2021-12-11, 12:59 AM

0

2

Unconfirmed

(Unassigned)

1.18.1

-