Skip to content

Mitigations for log4j vulnerability in Gradle buildsΒ #19300

Description

@big-guy

A RCE vulnerability in log4j has been found that affects certain combinations of Java and applications using log4j 2.

This is a critical vulnerability that is actively being exploited.

While Gradle itself is not directly impacted by this, we should provide some mitigations and recommendations for Gradle users.

The following has been done in Gradle:

  • Ensure Zinc compiler does not put a vulnerable Log4j on a classpath. This is done by upgrading log4j-core to 2.16.0 on the zinc compiler classpath when using the scala plugin.
  • Protect buildscript classpath from having vulnerable Log4j. This is done by adding a constraint that rejects known vulnerable versions [2.0, 2.16)and requires2.16.0`

More information on our blog post.

Activity

  1. added this to the 7.3.2 milestone on Dec 13, 2021
  2. self-assigned this
    on Dec 13, 2021
  3. ZakTaccardi commented on Dec 13, 2021

    @ZakTaccardi

    side note - but an interesting feature would be the ability to ensure that certain libraries/versions with vulnerabilities are not a part of the build - and if they are somehow introduced - fail the build.

  4. dhs-rec commented on Dec 15, 2021

    @dhs-rec

    Can't find a repo for the Gradle build-cache-node, so I report this here: Version 10.1, released Dec. 13th, also still ships with log4j2 2.15.0.

  5. joschi commented on Dec 15, 2021

    @joschi
    Contributor

    side note - but an interesting feature would be the ability to ensure that certain libraries/versions with vulnerabilities are not a part of the build - and if they are somehow introduced - fail the build.

    @ZakTaccardi That's already possible with dependency constraints, see https://blog.gradle.org/log4j-vulnerability and https://threadreaderapp.com/thread/1470845889166159873.html

  6. ljacomet commented on Dec 22, 2021

    @ljacomet
    Member

    Note that Gradle 7.3.3 will be released with a bump to log4j 2.17.0 - see #19360

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions