Xcode 13.2 contains Log4j vulnerability
developer.apple.com
developer.apple.com
It’s not surprising that more are preferring to use Electron, React Native, or Flutter to develop apps than to live with the bare metal Xcode toolchain and Apple APIs.
The Java / Kotlin + Gradle and JS development ecosystems are dramatically easier to live, despite the fact that Apple has the resources to do dramatically better.
Funny, because Electron, RN, and Flutter are the toys of mobile app development, serving mostly just one-man shops and toy applications--and even Android developers are going to agree.
And while I'm also of the opinion that Xcode has plenty of areas for improvement, you can't just extend the same commentary to Apple's APIs. Apple APIs are incredibly stable, well-architected, and so highly scalable that it's almost an embarrassment that Google gets all the rep for being an engineering powerhouse when the Android SDK has always been an incoherent hell of a mess since Android came out.
Do you have any data to back that up. As an iOS developer, that is not my experience at all.
The first is Google trends results for Flutter vs Swift globally in the last year.
https://trends.google.com/trends/explore?q=%2Fm%2F010sd4y3,%...
Along with StackOverflow’s 2021 report that shows Dart is more popular than Swift.
that... seems obviously wrong.
Flutter and Dart are used on a plethora of platforms, including Android which has a far larger market share than iOS alone, and Windows, which takes the cake on the desktop.
Swift is used only on Apple platforms, and mostly for iOS. The use of Swift on macOS, watchOS or server-side development is negligible.
I know Xcode is a piece of crap, but truly, nothing approaches the level of mindfuckery that is Gradle.
Honestly I would wager that the Developer Tools team has never been very happy about the size and quality (outdated JRE) of the upload tool
https://developer.apple.com/documentation/xcode-release-note...
I understand the log4j2 cve -- craft some input so that log4j does a lookup and insert your arbitrary code there.
But how does this being in XCode present a risk and what level of risk?
Is someone running XCode in a production server somewhere? The most likely case I could think of would be in a CI type server, and this would only be vulnerable when a build is getting is in progress?
It's not on the level of "my app runs on tomcat" type of bad, I wouldn't think.
And also once Xcode is patched, all of our teams are going to have to update immediately and that wipes out a whole day of work.
But again, just guessing here.
(Not that it's not bad)
Attackers would need to brute force or guess the right IP and port combination to do anything with this attack, so I don't think it will be a huge problem in practice. Just something to be aware of.
The Java version listed is already several outdated so I don't think log4j is the only security problem the uploading system introduces. I'm not sure why Apple isn't shipping a supported, patched JRE instead of their own bespoke implementation, but they seem to be behind on patches as a result.
I call it outrageous because the task itself (uploading to App Store Connect) don't require a separate runtime. It's likely an artefact from the past or convenience vehicle for whoever wrote it; another example of developer's convenience trumping user experience.
It would also be a download-on-first-use thing, much like Rosetta 2 or Xcode command line tools. Latest version only, updated regularly, updates delivered similarly to Safari Technology Preview. If you need a specific version, download it yourself.