Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6378


A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.


Published

2023-11-29T12:15:07.543

Last Modified

2024-11-29T12:15:06.597

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qos logback < 1.2.13 Yes
Application qos logback < 1.3.12 Yes
Application qos logback < 1.4.12 Yes

References