3 ms·
I ran this on my Mac and it found 2 instances of log4j jar files, both related to Xcode: /Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServi
by putlake 5y ago
I ran this on my Mac and it found 2 instances of log4j jar files, both related to Xcode:
/Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar
/System/Volumes/Data/Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar
Should I just delete them or is there a different mitigation? Apple needs to ship a patched Xcode version ASAP.
- suyash 5y agofinding the log4j jar is not the problem, it could have been patched. Finding the one that has vulnerable code is the issue.
- kjeetgill 5y agoIt so needs solving. Everyone should be using upgraded jars. Except as a stopgap, you shouldn't rely on patched Jars.
- layer8 5y agoSee the Xcode 13.2.1 release notes [0]: > Xcode contains a copy of the log4j library that has the CVE-2021-44228 security vulnerability. Xcode automatically downloads an updated version of this library and installs it into ~/Library/Caches/com.apple.amp.itmstransporter. When submitting apps to the App Store, Xcode uses the updated version of the library. (86390060) [0] https://developer.apple.com/documentation/xcode-release-notes/xcode-13_2_1-release-notes https://developer.apple.com/documentation/xcode-release-note...
- ddworken 5y agoYou can also use the --rewrite flag to automatically patch those files. This will remove the class that leads to the vulnerability and is generally a safe change.