DirectorySecurity Advisories
Sign In
Security Advisories

CGA-p5qq-x3qc-jpwx

Published

Last updated

https://images.chainguard.dev/security/CGA-p5qq-x3qc-jpwx
Package

zookeeper-3.9

Latest Update
Fixed
Fixed Version

3.9.1.0-r7

Aliases
  • CVE-2023-6378
  • GHSA-vmq6-5m68-f53m

Severity

7.1

High

CVSS V3

Summary

logback serialization vulnerability

Description

A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images