Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade log4j version to prevent vulnerability #1724

Merged
merged 1 commit into from
Dec 10, 2021
Merged

upgrade log4j version to prevent vulnerability #1724

merged 1 commit into from
Dec 10, 2021

Conversation

Nambers
Copy link
Contributor

@Nambers Nambers commented Dec 10, 2021

@Karlatemp Karlatemp added t:enhancement 类型: 现有功能上的优化 M 优先级: 主要 t:problem 类型: 不容易归类为特性或 bug 的综合问题 labels Dec 10, 2021
@Karlatemp Karlatemp requested a review from Him188 December 10, 2021 08:58
@Him188 Him188 added this to the 2.9.0-RC milestone Dec 10, 2021
@Him188 Him188 merged commit 07b303f into mamoe:dev Dec 10, 2021
@Nambers Nambers deleted the patch-2 branch December 10, 2021 14:17
@uebian uebian mentioned this pull request Dec 11, 2021
@AdoptOSS
Copy link
Contributor

鉴于该漏洞利用的便利性(Mirai会默认将很多聊天记录、事件记录输出到log)
及后果的严重性(有很大可能读取token、密码等信息)
建议发出安全警报

@sandtechnology
Copy link
Collaborator

鉴于该漏洞利用的便利性(Mirai会默认将很多聊天记录、事件记录输出到log) 及后果的严重性(有很大可能读取token、密码等信息) 建议发出安全警报

See #1726
除非开发者主动引入 否则不受漏洞影响

@AdoptOSS
Copy link
Contributor

See #1726
除非开发者主动引入 否则不受漏洞影响

从某一版本开始,log4j 是 Mirai 的推荐框架,原有的 MiraiLogger 已经被不推荐在外部使用

@Nambers
Copy link
Contributor Author

Nambers commented Dec 12, 2021

See #1726
除非开发者主动引入 否则不受漏洞影响

从某一版本开始,log4j 是 Mirai 的推荐框架,原有的 MiraiLogger 已经被不推荐在外部使用

可以针对mirai-logging-log4j发出警告吧,防止某些插件开发者可能用了然后以为这个库不包含log4j-api/log4j-core (?

@Him188
Copy link
Member

Him188 commented Dec 12, 2021

@AdoptOSS 这是因为用户不应该把 mirai 作为一个日志库使用。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
M 优先级: 主要 t:enhancement 类型: 现有功能上的优化 t:problem 类型: 不容易归类为特性或 bug 的综合问题
Projects
No open projects
Status: Fixed
Development

Successfully merging this pull request may close these issues.

5 participants