CVE-2023-6481 (High) detected in logback-core-1.4.12.jar #3817
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
Milestone
CVE-2023-6481 - High Severity Vulnerability
Vulnerable Library - logback-core-1.4.12.jar
logback-core module
Library home page: http://logback.qos.ch
Path to dependency file: /performance-test/build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.4.12/670c77fc6e71cbb24dfabc9fc125f7536ed7a4ab/logback-core-1.4.12.jar
Dependency Hierarchy:
Found in HEAD commit: 90bdaa7e7833bdd504c817e49d4434b4d8880f56
Found in base branch: main
Vulnerability Details
A serialization vulnerability in logback receiver component part of
logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service
attack by sending poisoned data.
Publish Date: 2023-12-04
URL: CVE-2023-6481
CVSS 3 Score Details (7.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2023-6481
Release Date: 2023-12-04
Fix Resolution: 1.4.14
The text was updated successfully, but these errors were encountered: