HIGH7.1
GHSA-vmq6-5m68-f53m
logback serialization vulnerability
Quick fix
GHSA-vmq6-5m68-f53m — ch.qos.logback:logback-classic: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.3.12</version> for ch.qos.logback:logback-classicDetails
A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/ch.qos.logback:logback-classic
Introduced in:
1.3.0Fixed in: 1.3.12Fix
# pom.xml: bump <version>1.3.12</version> for ch.qos.logback:logback-classicMaven/ch.qos.logback:logback-classic
Introduced in:
1.4.0Fixed in: 1.4.12Fix
# pom.xml: bump <version>1.4.12</version> for ch.qos.logback:logback-classicMaven/ch.qos.logback:logback-core
Introduced in:
1.3.0Fixed in: 1.3.12Fix
# pom.xml: bump <version>1.3.12</version> for ch.qos.logback:logback-coreMaven/ch.qos.logback:logback-core
Introduced in:
1.4.0Fixed in: 1.4.12Fix
# pom.xml: bump <version>1.4.12</version> for ch.qos.logback:logback-coreMaven/ch.qos.logback:logback-core
Introduced in:
0Fixed in: 1.2.13Fix
# pom.xml: bump <version>1.2.13</version> for ch.qos.logback:logback-coreMaven/ch.qos.logback:logback-classic
Introduced in:
0Fixed in: 1.2.13Fix
# pom.xml: bump <version>1.2.13</version> for ch.qos.logback:logback-classicReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-6378[ADVISORY]
- https://github.com/qos-ch/logback/issues/745#issuecomment-1836227158[WEB]
- https://github.com/qos-ch/logback/commit/9c782b45be4abdafb7e17481e24e7354c2acd1eb[WEB]
- https://github.com/qos-ch/logback/commit/b8eac23a9de9e05fb6d51160b3f46acd91af9731[WEB]
- https://github.com/qos-ch/logback/commit/bb095154be011267b64e37a1d401546e7cc2b7c3[WEB]
- https://github.com/qos-ch/logback[PACKAGE]
- https://logback.qos.ch/manual/receivers.html[WEB]
- https://logback.qos.ch/news.html#1.2.13[WEB]
- https://logback.qos.ch/news.html#1.3.12[WEB]
- https://security.netapp.com/advisory/ntap-20241129-0012[WEB]