Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-8088

Опубликовано: 20 мар. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.7.25-3
cosmic

not-affected

1.7.25-3
devel

not-affected

1.7.25-3
esm-apps/bionic

not-affected

1.7.25-3
esm-apps/xenial

not-affected

slf4j-ext not built in package
esm-infra-legacy/trusty

not-affected

slf4j-ext not built in package
precise/esm

DNE

trusty

not-affected

slf4j-ext not built in package
trusty/esm

not-affected

slf4j-ext not built in package

Показывать по

EPSS

Процентиль: 74%
0.00836
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

CVSS3: 9.8
nvd
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

CVSS3: 9.8
debian
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before ...

suse-cvrf
больше 7 лет назад

Security update for slf4j

suse-cvrf
больше 7 лет назад

Security update for slf4j

EPSS

Процентиль: 74%
0.00836
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3