NA

CVE-2023-6378

Published: 29/11/2023 Updated: 05/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an malicious user to mount a Denial-Of-Service attack by sending poisoned data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qos logback

Vendor Advisories

Synopsis Important: Red Hat Integration Camel for Spring Boot 403 release security update Type/Severity Security Advisory: Important Topic Red Hat Integration Camel for Spring Boot 403 release and security update is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabilit ...
Debian Bug report logs - #1057423 logback: CVE-2023-6378 Package: src:logback; Maintainer for src:logback is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 4 Dec 2023 20:00:02 UTC Severity: important Tags: security, upstream F ...
DescriptionThe MITRE CVE dictionary describes this issue as: A serialization vulnerability in logback receiver component part of logback version 1411 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data ...

Github Repositories

Playing around with a tool for updating POM dependencies

pombump Programmatically manipulate maven (pomxml) dependencies Overview For easier patchability, add ways to selectively bump versions for dependencies The idea is just like gobump but for java Usage The idea is that there are some patches that should be applied to the upstream pomxml file You can specify these via --dependencies flag, or via --patch-file You can also u

DAI-PW4 - Drink Manager The Drink Manager API is a web service designed for managing a database of drinks It operates on HTTP port 8080 This API follows the CRUD (Create, Read, Update, Delete) pattern, offering endpoints to create, retrieve, update, or delete drinks You can also place an order This tool is particularly useful if you need to manage a dynamic drink inventory

Playing around with a tool for updating POM dependencies

pombump Programmatically manipulate maven (pomxml) dependencies Overview For easier patchability, add ways to selectively bump versions for dependencies The idea is just like gobump but for java Usage The idea is that there are some patches that should be applied to the upstream pomxml file You can specify these via --dependencies flag, or via --patch-file You can also u