CVE-2023-6378: Logback "receiver" DOS vulnerability
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Other sources
A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html
— GitHub
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-6378?
CVE-2023-6378 is a serialization vulnerability in the logback receiver component, allowing an attacker to mount a Denial-of-Service attack by sending poisoned data.
How severe is CVE-2023-6378?
CVE-2023-6378 has a severity level of 7.1, which is classified as high.
Which software versions are affected by CVE-2023-6378?
Logback versions 1.4.0 to 1.4.12 and versions 1.3.0 to 1.3.12 of logback-core and logback-classic are affected by CVE-2023-6378.
How can I fix CVE-2023-6378?
To fix CVE-2023-6378, upgrade to logback version 1.4.12 for logback-core and logback-classic.
Where can I find more information about CVE-2023-6378?
You can find more information about CVE-2023-6378 in the logback news, the NIST vulnerability database, and the logback GitHub commit.