Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-668q-qrv7-99fm

Опубликовано: 17 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

Deserialization of Untrusted Data in logback

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

Пакеты

Наименование

ch.qos.logback:logback-core

maven
Затронутые версииВерсия исправления

< 1.2.9

1.2.9

EPSS

Процентиль: 85%
0.02604
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 4 лет назад

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

CVSS3: 6.6
redhat
около 4 лет назад

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

CVSS3: 6.6
nvd
около 4 лет назад

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

CVSS3: 6.6
debian
около 4 лет назад

In logback version 1.2.7 and prior versions, an attacker with the requ ...

suse-cvrf
почти 3 года назад

Security update for maven and recommended update for antlr3, minlog, sbt, xmvn

EPSS

Процентиль: 85%
0.02604
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-502