A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ch.qos.logback:logback-classic(Maven) | 1.3.0 | 1.3.12 | N/A |
| ch.qos.logback:logback-classic(Maven) | 1.4.0 | 1.4.12 | N/A |
| ch.qos.logback:logback-core(Maven) | 1.3.0 | 1.3.12 | N/A |
| ch.qos.logback:logback-core(Maven) | 1.4.0 | 1.4.12 | N/A |
| ch.qos.logback:logback-core(Maven) | 0 | 1.2.13 | N/A |
| ch.qos.logback:logback-classic(Maven) | 0 | 1.2.13 | N/A |
CVSS Metrics