OESA-2023-1946
Dashboard / Vulnerabilities / OESA-2023-1946
Summary: logback security update
Details: Logback is intended as a successor to the popular log4j project. Security Fix(es): A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data. (CVE-2023-6378) A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data. (CVE-2023-6481)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1946, https://nvd.nist.gov/vuln/detail/CVE-2023-6378, https://nvd.nist.gov/vuln/detail/CVE-2023-6481
Affected packages
Package
Name: logback
Purl: pkg:rpm/openEuler/logback&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
