QID 996112
Date Published: 2023-11-30
QID 996112: Java (Maven) Security Update for ch.qos.logback:logback-classic (GHSA-vmq6-5m68-f53m)
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vmq6-5m68-f53m for updates and patch information.
Vendor References
- GHSA-vmq6-5m68-f53m -
github.com/advisories/GHSA-vmq6-5m68-f53m
CVEs related to QID 996112
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vmq6-5m68-f53m | ch.qos.logback:logback-classic |
|