It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
DISCLAIMER: I know nothing about programming and such, so forgive me if I fail to understand fundamental stuff here.

Just stumbled upon a bunch of articles claiming a serious exploit has been found with a logging utility called Log4j which presumably allows attackers to freely execute code on your computer. Here's a link to one article:
https://arstechnica.com/information-technology/2021/12/minecraft-and-other-apps-face-serious-threat-from-new-code-execution-bug/

Most articles I've read have mentioned that this Log4j tool is part of loads of programs - Minecraft and Steam are explicitly mentioned in most articles, though I've seen Valve staff say that Steam should be safe.

Now, since I have zero programming knowledge, I'm wondering if we could get any official comment by GOG staff on whether GOG Galaxy is safe to use right now (I have no idea if Galaxy even uses Log4j, though).

Looking into this thing, I've seen some articles on the web referring to previous instances where GOG were informed of exploints and reacted insufficiently, both in terms of fixing the exploits and communicating with the people who brought those exploits to GOG's attention (see https://www.positronsecurity.com/blog/2020-08-13-gog-galaxy_client-local-privilege-escalation_deuce/ ). So I'm kinda worried now that Galaxy might be open to this exploit and we'll never know because GOG is terrible at communicating. Perhaps in lieu of an official responst, some tech-savvy GOG user could look into this, even if it's just to warn other users?
The bit of Steam that is affected is Valve's servers, not the client.

The GOG galaxy client doesn't use Java, so it is not affected. I can't speak for the server backend, or for any of the individual games.

That being said, auto updating of games could cause all manner of nastiness if GOG's update server gets compromised.

.
Post edited December 12, 2021 by Mortius1
from just looking around minecraft and community support there(which i help out sometimes in various location & i've met more people who knows more details) seems to only effect whatever is using java systems
Thank you both for clarifying! I wouldn't have even known how to check if Galaxy uses Java.
oh modular plugin programming so secure as usual :)