Logback is intended as a successor to the popular log4j project.
Security Fix(es):
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
(CVE-2023-6378)
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
(CVE-2023-6481)
{ "severity": "High" }
{ "src": [ "logback-1.2.8-3.oe2203.src.rpm", "logback-1.2.8-3.oe2203sp1.src.rpm", "logback-1.2.8-3.oe2203sp2.src.rpm" ], "noarch": [ "logback-access-1.2.8-3.oe2203.noarch.rpm", "logback-examples-1.2.8-3.oe2203.noarch.rpm", "logback-help-1.2.8-3.oe2203.noarch.rpm", "logback-1.2.8-3.oe2203.noarch.rpm", "logback-help-1.2.8-3.oe2203sp1.noarch.rpm", "logback-access-1.2.8-3.oe2203sp1.noarch.rpm", "logback-1.2.8-3.oe2203sp1.noarch.rpm", "logback-examples-1.2.8-3.oe2203sp1.noarch.rpm", "logback-access-1.2.8-3.oe2203sp2.noarch.rpm", "logback-1.2.8-3.oe2203sp2.noarch.rpm", "logback-help-1.2.8-3.oe2203sp2.noarch.rpm", "logback-examples-1.2.8-3.oe2203sp2.noarch.rpm" ] }