FAForever Forums
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Login

    Security Issue log4j

    Scheduled Pinned Locked Moved FAF support (client and account issues)
    11 Posts 5 Posters 683 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Sheikah
      last edited by

      Hey @KeuleGrob one of the client dependencies uses log4j however the client itself doesnt not use log4j. Also that dependency has all logging facilities disabled so there is no threat from log4j in the client

      1 Reply Last reply Reply Quote 1
      • K Offline
        KeuleGrob
        last edited by

        Hi Sheika, thanks for your fast reply.
        I cannot evaluate the complex security circumstances in this special case.
        Is it still possible to use the Log4j version > = 2.16 with the next patch ?

        1 Reply Last reply Reply Quote 0
        • S Offline
          Sheikah
          last edited by Sheikah

          We have to get the dependency to update their dependencies but we are working with them to do so and should be updated next patch

          1 Reply Last reply Reply Quote 0
          • UvesoU Offline
            Uveso
            last edited by

            @KeuleGrob

            we don't need to update the log4j, we can simply set log4j2.formatMsgNoLookups = true
            and the backdoor is closed.

            1 Reply Last reply Reply Quote 0
            • K Offline
              KeuleGrob
              last edited by

              @Uveso
              I sincerely hope you are right. This security issue deletes our chrismas holidays include Weekend.
              Where do i set the formatMsgNoLookups Parameter? Is there for example a XML configuration File in the FAF Client Folder?

              1 Reply Last reply Reply Quote 0
              • AskaholicA Offline
                Askaholic
                last edited by

                If that dependency has all logging disabled anyways can you just delete the log4j jars?

                1 Reply Last reply Reply Quote 0
                • S Offline
                  Sheikah
                  last edited by

                  Probably but haven't tested myself

                  1 Reply Last reply Reply Quote 0
                  • F Offline
                    fractal
                    last edited by

                    and how did it all end here? deleted? turned off? have you come to terms with the current situation?

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      Sheikah
                      last edited by

                      The dependency was updated to the newest log4j, although the client still never interacts with any of the logging there anyway.

                      F 1 Reply Last reply Reply Quote 0
                      • F Offline
                        fractal @Sheikah
                        last edited by

                        @sheikah said in Security Issue log4j:

                        The dependency was updated to the newest log4j, although the client still never interacts with any of the logging there anyway.

                        cool! thank you for responding!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post