Upgrade to log4j2

Post here your questions about SFS2X. Here we discuss all server-side matters. For client API questions see the dedicated forums.

Moderators: Lapo, Bax

Post Reply
User avatar
mete2221
Posts: 82
Joined: 30 Aug 2017, 17:01

Upgrade to log4j2

Post by mete2221 »

log4j is no longer standard and has a lot of vulnerabilities.

https://security.snyk.io/package/maven/ ... g4j/1.2.17
User avatar
Lapo
Site Admin
Posts: 23438
Joined: 21 Mar 2005, 09:50
Location: Italy

Re: Upgrade to log4j2

Post by Lapo »

Hi,
we know about the security issues that have been piling up in the past years, however none of these vulnerabilities are relevant to SmartFoxServer 2X.

The default SFS2X logging config does not use the Chainsaw component or the SocketAppender, which are the two main vulnerable elements. The remaining issues listed in the article require write access to the log4j config, which means that the security of the system is already compromised.

As for future upgrades, we'll move to LogBack (always using the slf4j interface)

Cheers
Lapo
--
gotoAndPlay()
...addicted to flash games
Post Reply