log4shell
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
log4shell [2021/12/11 18:12] – alexander01998 | log4shell [2023/01/21 23:18] (current) – [How to test if you are affected] fix typo alexander01998 | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== Log4Shell Vulnerability ====== | ====== Log4Shell Vulnerability ====== | ||
- | Log4Shell ([[https:// | + | Log4Shell ([[https:// |
Anyone can exploit this vulnerability by simply typing a special message into the Minecraft chat. | Anyone can exploit this vulnerability by simply typing a special message into the Minecraft chat. | ||
- | If you are playing on a Minecraft | + | Log4Shell is caused by certain versions of the Log4j library, which are included in all Minecraft |
- | Log4Shell is caused by certain versions of the Log4j library, which are included in Minecraft 1.7 - 1.18. Both Minecraft clients and Minecraft servers can be vulnerable to this exploit. | + | ===== Why care? ===== |
- | ===== Affected Wurst versions ===== | + | If you are playing on a Minecraft server and your Minecraft installation is vulnerable (even if the server is patched), then another player could, for example, install a virus on your computer by simply sending you a chat message.((They could also [[https:// |
- | ^Wurst MC Version^Status^Patched by^How to fix^ | + | ===== Affected versions ===== |
+ | |||
+ | ==== Wurst Client ==== | ||
+ | |||
+ | ^MC Version^Status^Patched by^How to fix^ | ||
+ | |Wurst MC 1.19+|**< | ||
|Wurst MC 1.18.1|**< | |Wurst MC 1.18.1|**< | ||
- | |Wurst MC 1.18|**< | + | |Wurst MC 1.18|**< |
- | |Wurst MC 1.17.x|**< | + | |Wurst MC 1.17.1|**< |
- | |Wurst MC 1.16.x|**< | + | |Wurst MC 1.17|**< |
- | |Wurst MC 1.15.x|**< | + | |Wurst MC 1.16.x|**< |
- | |Wurst MC 1.14.x|**< | + | |Wurst MC 1.15.x|**< |
- | |Wurst MC 1.12.x|**< | + | |Wurst MC 1.14.x|**< |
+ | |Wurst MC 1.12.x|**< | ||
+ | |ForgeWurst MC 1.12.2|**< | ||
|Wurst MC 1.11.x|< | |Wurst MC 1.11.x|< | ||
+ | |ForgeWurst MC 1.11.2|< | ||
|Wurst MC 1.10.x|< | |Wurst MC 1.10.x|< | ||
|Wurst MC 1.9.x|< | |Wurst MC 1.9.x|< | ||
- | |Wurst MC 1.8.x|**< | + | |Wurst MC 1.8.x|**< |
|Wurst MC 1.7.x|< | |Wurst MC 1.7.x|< | ||
- | **Note: | + | **Note: |
+ | |||
+ | ==== Wolfram Client ==== | ||
+ | |||
+ | ^MC Version^Status^Patched by^How to fix^ | ||
+ | |Wolfram MC 1.12.x|**< | ||
+ | |Wolfram MC 1.11.x|**< | ||
+ | |Wolfram MC 1.10.x|**< | ||
+ | |Wolfram MC 1.9.4|**< | ||
+ | |Wolfram MC 1.8.x|**< | ||
+ | |||
+ | ==== Mo Glass ==== | ||
+ | |||
+ | ^MC Version^Status^Patched by^How to fix^ | ||
+ | |Mo Glass MC 1.19+|**< | ||
+ | |Mo Glass MC 1.18.1|**< | ||
+ | |Mo Glass MC 1.18|**< | ||
+ | |Mo Glass MC 1.17.1|**< | ||
+ | |Mo Glass MC 1.17|**< | ||
+ | |Mo Glass MC 1.16.x|**< | ||
+ | |Mo Glass MC 1.15.x|**< | ||
+ | |Mo Glass MC 1.14.x|**< | ||
+ | |||
+ | **Note:** Mo Glass 1.6 and later versions won't even launch when used with a Fabric Loader version older than v0.12.10. This ensures that they cannot accidentally | ||
+ | |||
+ | ==== WI Zoom ==== | ||
+ | |||
+ | ^MC Version^Status^Patched by^How to fix^ | ||
+ | |WI Zoom MC 1.19+|**< | ||
+ | |WI Zoom MC 1.18.1|**< | ||
+ | |WI Zoom MC 1.18|**< | ||
+ | |WI Zoom MC 1.17.x|**< | ||
+ | |WI Zoom MC 1.16.x|**< | ||
+ | |WI Zoom MC 1.15.x|**< | ||
+ | |WI Zoom MC 1.14.x|**< | ||
+ | |WI Zoom MC 1.12.2|**< | ||
+ | |||
+ | ===== How to check your Wurst version ===== | ||
+ | |||
+ | {{: | ||
+ | |||
+ | Your Wurst version is displayed in the top left corner of the screen. | ||
===== How to check your Fabric Loader version ===== | ===== How to check your Fabric Loader version ===== | ||
- | ==== Official | + | |
+ | **Note:** Fabric Loader 0.12.12 further improves the Log4Shell patch to cover cases published by CVE-2021-45046. This doesn' | ||
+ | |||
+ | ==== Official | ||
Click on the " | Click on the " | ||
- | {{: | + | {{: |
==== MultiMC ==== | ==== MultiMC ==== | ||
- | Click on "Edit Instance" | + | **Note:** MultiMC has released their own patch for the Log4Shell exploit.((https:// |
- | {{:log4shell-loader-version-multimc.webp|}} | + | Click on "Edit Instance" |
- | **Note:** MultiMC has released their own patch for the Log4Shell exploit. You might be fine even with an older Fabric Loader version, but you should [[# | + | {{:log4shell-loader-version-multimc.webp|Checking the Fabric Loader version in MultiMC}} |
===== How to test if you are affected ===== | ===== How to test if you are affected ===== | ||
Line 51: | Line 103: | ||
Then check your log file (default: '' | Then check your log file (default: '' | ||
- | If your Minecraft installation is **vulnerable**, | + | If your Minecraft installation is **vulnerable**, |
< | < | ||
[17:32:25] [Client thread/ | [17:32:25] [Client thread/ | ||
Line 136: | Line 188: | ||
{{tag> | {{tag> | ||
---- struct data ---- | ---- struct data ---- | ||
+ | hack.name | ||
+ | hack.image | ||
+ | hack.category | ||
+ | hack.in-game description : | ||
+ | hack.default keybind : | ||
+ | hack.source code : | ||
---- | ---- | ||
log4shell.1639246367.txt.gz · Last modified: 2021/12/11 18:12 by alexander01998