saros-project / saros

Open Source IDE plugin for distributed collaborative software development
https://www.saros-project.org
GNU General Public License v2.0
160 stars 52 forks source link

Potential for Log4j exploit #1153

Closed anematode closed 2 years ago

anematode commented 2 years ago

As far as I can tell, this project uses a version of Log4j 2 <2.16.0, which is needed to fix the recent vulnerability. I believe I'm pretty close to obtaining a working exploit that just sends a malicious XMPP request that is eventually logged, but I can't confirm that yet—I'll post here if I can make it work. In any case, bumping the version is probably a good idea, as anyone with Eclipse/IntelliJ simply being open could be vulnerable.