DirectorySecurity Advisories
Sign In
Security Advisories

CGA-69p6-hjq3-r85h

Published

Last updated

https://images.chainguard.dev/security/CGA-69p6-hjq3-r85h
Package

cassandra-4.0

Latest Update
Not affected
Aliases
  • CVE-2023-6378
  • GHSA-vmq6-5m68-f53m

Severity

7.1

High

CVSS V3

Summary

logback serialization vulnerability

Description

A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images