Modrinth · Minecraft mod
Healer
Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2
Quick answer
Which Healer release should I use?
Healer 1.2.1 targets 1.7.2, 1.7.3, 1.7.4 with Forge. Installation on the client is optional. Installation on the dedicated server is optional. No extra mods listed for this file.
Where it goes
Is Healer required on the client, server, or both?
Installation on the client is optional. Installation on the dedicated server is optional.
The source marks this as usable on both the client and server.
What else does Healer 1.2.1 need?
1.2.1. Change the file and its required mods may change too.
This file does not list any required mods. Do not add a library just because a different file uses it.
This file does not list any required or optional mods.
Before you install it
Add Healer without breaking your instance.
Built for Healer 1.2.1. Pick another file and the loader, install side or required mods may change.
- 01
Stick to this file
Use 1.2.1. It targets 1.7.2, 1.7.3, 1.7.4 with Forge; another release may have different loader, side or dependency requirements.
- 02
Bring the mods it needs
This file does not list any required mods. Do not add a library just because a different file uses it.
- 03
Put it on the correct side
Installation on the client is optional. Installation on the dedicated server is optional.
- 04
Pick the file you checked
Use the “Get this file” button beside 1.2.1. It opens that exact file at the source.
About this project
What does Healer add?
Patch up security vulnerbility CVE-2021-44228 (also known as Log4Shell) for minecraft forge 1.7.10 - 1.12.2, by removing JNDI lookup from Interpolator using reflection and replace the default LoggerContextFactory to catch any LoggerContext loaded after this mod. For more specific technical explainations on how I patched it, please refer to the source code instead.
Currently only works for minecraft 1.12 and before. Tested on 1.7.10 and 1.12.2.
Compatibility
If any mod tries to programatically tweak logging configuration, they will fail miserably due to the exhaustive patching. To fix this, healer postpones the patching late enough, until said mods are done with their editing.
As of date, healer has built in support for these mods.
- ForgeEssentials
If you have other mods crashing with log lines like ClassCastException: cannot cast XXXXXXXX to org.apache.logging.log4j.core.impl.Log4jContextFactory, then you have step on one of these mods.
To fix this, complain at my issue tracker, or add -Dnet.glease.healer.patch_stage=XXXX to your JVM launch argument, where XXXX can be any of PRELOAD, PREINIT, INIT, POSTINIT (in time order, with earliest as the first). PREINIT is usually enough to mitigate the problem, POSTINIT should be enough to fix all problem.
To ordinary players
- If your launcher has patched this already, you will not need this mod to patch the vulnerability.
- If you applied mojang's fix, you will not need this mod to patch the vulnerability.
- If you have FoamFix for 1.7, you will not need this mod to patch the vulnerability.
- If you have used other fixing mods, ask their original authors if they can "catch any LoggerContext loaded after their mod", if yes, you will not need this mod. Otherwise, replace that mod with this mod, or use a launcher that does patching for you, e.g. MultiMC.
To modpack makers
- I suggest you to include this mod in your client pack, if it is intended for minecraft 1.7~1.12.2. This will protect your users who is still not aware of this and happen to use a launcher that hasn't patched this.
- If you also distribute a server pack, and it is intended for minecraft 1.7~1.12.2, adding this mod is not necessary if you applied mojang's fix. However, since many people don't use the StartServer.bat (or something alike) that come with your server pack, chances are they will not use mojang's fixed log4j2.xml. Technically you should not distribute an edited minecraft_server-1.7.10.jar, so adding this jar would be the most straightfoward way of ensuring the user getting a fix.
Project description from Modrinth.
Pick your setup
Healer by Minecraft version and loader
Choose the version and loader you play, then open the matching release.
17w18b
1 loader build17w18a
1 loader build17w17b
1 loader build17w17a
1 loader build17w16b
1 loader build17w16a
1 loader build17w15a
1 loader build17w14a
1 loader build17w13b
1 loader build17w13a
1 loader build17w06a
1 loader buildShowing the newest 12 of 230 game versions. Older files are in the list below.
Check the dependencies, then try the file in a copied instance before changing a world you care about.
Recent files
Healer versions and loaders
1.2.1
Healer-1.2.1.jar
25 Nov 2024
1.2.1
Healer-1.2.1-sources.jar
27 Jan 2023
1.2.0
Healer-1.2.0.jar
16 Dec 2021
1.1.0
Healer-1.1.0.jar
10 Dec 2021
Looking for an older file? The official Modrinth project page is in Resources.