A RCE vulnerability in log4j has been found that affects certain combinations of Java and applications using log4j 2.
This is a critical vulnerability that is actively being exploited.
While Gradle itself is not directly impacted by this, we should provide some mitigations and recommendations for Gradle users.
The following has been done in Gradle:
- Ensure Zinc compiler does not put a vulnerable Log4j on a classpath. This is done by upgrading
log4j-core to 2.16.0 on the zinc compiler classpath when using the scala plugin.
- Protect buildscript classpath from having vulnerable Log4j. This is done by adding a constraint that rejects known vulnerable versions [2.0, 2.16)
and requires2.16.0`
More information on our blog post.
A RCE vulnerability in log4j has been found that affects certain combinations of Java and applications using log4j 2.
This is a critical vulnerability that is actively being exploited.
While Gradle itself is not directly impacted by this, we should provide some mitigations and recommendations for Gradle users.
The following has been done in Gradle:
log4j-coreto2.16.0on the zinc compiler classpath when using the scala plugin.and requires2.16.0`More information on our blog post.