Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision |
news:cve_says_what [2021/12/10 23:47] – created ch1b1 | news:cve_says_what [2021/12/23 00:25] (current) – [22 Dec 2021: Service Restored!] ch1b1 |
---|
Our version of Minecraft is affected by [[https://nvd.nist.gov/vuln/detail/CVE-2021-44228|CVE-2021-44228]]. A "CVE" is what happens when programmers make bad decisions… like permitting a logging framework to resolve URLs, connect to servers, download content, and then to execute that content as instructions. | Our version of Minecraft is affected by [[https://nvd.nist.gov/vuln/detail/CVE-2021-44228|CVE-2021-44228]]. A "CVE" is what happens when programmers make bad decisions… like permitting a logging framework to resolve URLs, connect to servers, download content, and then to execute that content as instructions. |
| |
''theparadox.us'' has many defenses against intrusion. While there is no evidence that the server was actually compromised, we will carefully sanitize our high-contact surfaces to ensure that nothing nasty can remain. | ''theparadox.us'' has many defenses against intrusion. While there is no evidence that the server was actually compromised, we will carefully sanitize our high-contact surfaces to ensure that nothing nasty can remain. **Expect a day or two of downtime as we get this sorted out.** |
| |
It is unclear if Mojang will release any further patches to Minecraft 1.16. It is also unclear if any of the existing mitigations actually make the old code safe. We may be required to update to [[https://minecraft.fandom.com/wiki/Java_Edition_1.18|Minecraft 1.18]]. | It is unclear if Mojang will release any further patches to Minecraft 1.16. It is also unclear if any of the existing mitigations actually make the old code safe. We may be required to update to [[https://minecraft.fandom.com/wiki/Java_Edition_1.18|Minecraft 1.18]]. |
| |
| ===== 22 Dec 2021: Service Restored! ===== |
| |
| Just in time for the holidays, all services are now operational. Better late than never, right? Security patches have allowed us to remain on Minecraft 1.16 for now, and everything should be right where you left it. |
| |
| If you can't remember //where// that is, that's your own problem. |
| |
| Play on… but first, learn how to protect yourself from the [[https://www.minecraft.net/en-us/article/important-message--security-vulnerability-java-edition|compuvirus]]. |