Mojira Archive
MCL-20870

CVE-2021-44228 may affect legacy (pre 1.7) clients via LegacyLauncher

LegacyLauncher aka legacywrapper uses a vulnerable version of log4j, to my understanding the games logs are routed through it, so this may make Minecraft versions before Release 1.7 vulnerable to the recently disclosed & fixed exploit that affected 1.7+.

This should only affect legacy clients, servers will be unaffected.

I've noticed someone has opened a pull request around this exploit, so you may be able to merge this.

https://github.com/Mojang/LegacyLauncher/pull/34

ps: it'd be neat if you reviewed the other PRs while there

Works As Intended

Codie Stella

2021-12-10, 08:06 PM

2022-02-02, 02:09 PM

2022-02-02, 01:52 PM

0

2

Plausible

2.2.8354 (Linux), 2.2.8351 (Windows), 2.2.8352 (New Windows App), 2.2.8353 (Mac)

-