Description
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Remediation
References
https://logback.qos.ch/news.html#1.3.12
https://logback.qos.ch/news.html#1.3.14
Related Vulnerabilities
CVE-2017-20165 Vulnerability in npm package debug
CVE-2022-29249 Vulnerability in maven package io.github.javaezlib:javaez
CVE-2018-19048 Vulnerability in maven package org.webjars.bower:simditor
CVE-2023-0868 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js