Описание
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 1:1.2.3-2ubuntu1~18.04.1 |
| devel | not-affected | |
| esm-apps/bionic | not-affected | 1:1.2.3-2ubuntu1~18.04.1 |
| esm-apps/focal | not-affected | |
| esm-apps/jammy | not-affected | |
| esm-apps/noble | not-affected | |
| esm-apps/xenial | needed | |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | |
| groovy | not-affected |
Показывать по
Ссылки на источники
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
QOS.ch Logback before 1.2.0 has a serialization vulnerability affectin ...
QOS.ch Logback vulnerable to Deserialization of Untrusted Data
Уязвимость класса logback-core в файле QOS.ch библиотеки Jackson-databind, позволяющая нарушителю выполнить произвольный код
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3