CurseForge · Minecraft mod
Log4JPatcher
A java agent to patch the CVE in L4J2
Quick answer
Which Log4JPatcher release matches 1.7.7 Fabric?
Log4jPatcher-1.0.1.jar targets 1.7.6, 1.16-Snapshot, 1.17.1 with Fabric, Forge. The project page does not say whether this file belongs on the client, dedicated server, or both. No extra mods listed for this file.
Where it goes
Is Log4JPatcher required on the client, server, or both?
The project page does not say whether this file belongs on the client, dedicated server, or both.
The source does not explicitly classify this release as client-only or server-only.
What else does Log4jPatcher-1.0.1.jar need?
Log4jPatcher-1.0.1.jar on 1.7.7 Fabric. Every mod below is checked against that same setup.
This file does not list any required mods. Do not add a library just because a different file uses it.
This file does not list any required or optional mods.
Before you install it
Add Log4JPatcher without breaking your instance.
Built for Log4jPatcher-1.0.1.jar on 1.7.7 Fabric. Pick another file and the loader, install side or required mods may change.
- 01
Stick to this file
Use Log4jPatcher-1.0.1.jar. It targets 1.7.6, 1.16-Snapshot, 1.17.1 with Fabric, Forge; another release may have different loader, side or dependency requirements.
- 02
Bring the mods it needs
This file does not list any required mods. Do not add a library just because a different file uses it.
- 03
Put it on the correct side
The project page does not say whether this file belongs on the client, dedicated server, or both.
- 04
Pick the file you checked
Use the “Get this file” button beside Log4jPatcher-1.0.1.jar. It opens that exact file at the source.
About this project
What does Log4JPatcher add?
Log4jPatcher
A Java Agent based mitigation for Log4j2 JNDI exploits.
This agent employs 2 patches:
- Disabling all Lookup conversions (on supported Log4j versions) in
org.apache.logging.log4j.core.pattern.MessagePatternConverterby settingnoLookupsto true in the constructor. - Disabling the
org.apache.logging.log4j.core.lookup.JndiLookupclass by just returningnullin itslookupfunction.
To use
Add -javaagent:Log4jPatcher.jar as a JVM argument.
More information on this CVE and it's impact is available at CreeperBlog (creeperhost.net)
Project description from CurseForge.
Pick your setup
Log4JPatcher by Minecraft version and loader
Choose the version and loader you play, then open the matching release.
1.18-Snapshot
2 loader builds1.18
2 loader builds1.17.1
2 loader builds1.17-Snapshot
2 loader builds1.17
2 loader builds1.16.5
2 loader builds1.16.4
2 loader builds1.16.3
2 loader builds1.16.2
2 loader builds1.16.1
2 loader builds1.16-Snapshot
2 loader buildsShowing the newest 12 of 86 game versions. Older files are in the list below.
Check the dependencies, then try the file in a copied instance before changing a world you care about.
Recent files
Log4JPatcher versions and loaders
Log4jPatcher-1.0.1.jar
11 Dec 2021
Log4jPatcher-1.0.0.jar
10 Dec 2021
Looking for an older file? The official CurseForge project page is in Resources.
