Logback is intended as a successor to the popular log4j project.
Security Fix(es):
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
(CVE-2023-6378)
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
(CVE-2023-6481)
{
"severity": "High"
}{
"src": [
"logback-1.2.8-3.oe2203.src.rpm",
"logback-1.2.8-3.oe2203sp1.src.rpm",
"logback-1.2.8-3.oe2203sp2.src.rpm"
],
"noarch": [
"logback-access-1.2.8-3.oe2203.noarch.rpm",
"logback-examples-1.2.8-3.oe2203.noarch.rpm",
"logback-help-1.2.8-3.oe2203.noarch.rpm",
"logback-1.2.8-3.oe2203.noarch.rpm",
"logback-help-1.2.8-3.oe2203sp1.noarch.rpm",
"logback-access-1.2.8-3.oe2203sp1.noarch.rpm",
"logback-1.2.8-3.oe2203sp1.noarch.rpm",
"logback-examples-1.2.8-3.oe2203sp1.noarch.rpm",
"logback-access-1.2.8-3.oe2203sp2.noarch.rpm",
"logback-1.2.8-3.oe2203sp2.noarch.rpm",
"logback-help-1.2.8-3.oe2203sp2.noarch.rpm",
"logback-examples-1.2.8-3.oe2203sp2.noarch.rpm"
]
}