From c31269a358def5837dce99f0ffcb3761b81727b1 Mon Sep 17 00:00:00 2001 From: Glavo Date: Fri, 10 Dec 2021 03:26:21 +0800 Subject: [PATCH] Disable message pattern lookup by default --- .../main/java/org/jackhuang/hmcl/launch/DefaultLauncher.java | 3 +++ 1 file changed, 3 insertions(+) diff --git a/HMCLCore/src/main/java/org/jackhuang/hmcl/launch/DefaultLauncher.java b/HMCLCore/src/main/java/org/jackhuang/hmcl/launch/DefaultLauncher.java index 49218bb82..fd0227c4d 100644 --- a/HMCLCore/src/main/java/org/jackhuang/hmcl/launch/DefaultLauncher.java +++ b/HMCLCore/src/main/java/org/jackhuang/hmcl/launch/DefaultLauncher.java @@ -178,6 +178,9 @@ public class DefaultLauncher extends Launcher { res.addDefault("-Dfml.ignoreInvalidMinecraftCertificates=", "true"); res.addDefault("-Dfml.ignorePatchDiscrepancies=", "true"); + + // Fix RCE vulnerability of log4j2 + res.addDefault("-Dlog4j2.formatMsgNoLookups=", "true"); } Proxy proxy = options.getProxy();