Vulnerability Description
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qos | Logback | >= 1.2.0, < 1.2.13 |
Related Weaknesses (CWE)
References
- https://logback.qos.ch/news.html#1.3.12Release Notes
- https://logback.qos.ch/news.html#1.3.12Release Notes
- https://security.netapp.com/advisory/ntap-20241129-0012/
FAQ
What is CVE-2023-6378?
CVE-2023-6378 is a vulnerability with a CVSS score of 7.1 (HIGH). A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
How severe is CVE-2023-6378?
CVE-2023-6378 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6378?
Check the references section above for vendor advisories and patch information. Affected products include: Qos Logback.