DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-pcf9-h2fp-9f4m

Package

ontop-fips

Component

logback-core

Latest update

Fixed

Fixed version

5.5.0-r10

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-12798

Updates

Status

Fixed

Fixed version

5.5.0-r10

Status

Pending upstream fix

Impact

Upgrading logback-core from 1.2.13 to 1.3.16 introduces breaking changes as SLF4J 2.0.x is incompatible with Spring Boot 2.7.x:

  • Spring Boot 2.7.x to 3.x migration required
  • Current blocker: SLF4J 2.0 uses ServiceLoader mechanism (StaticLoggerBinder removed), Spring Boot 2.x uses Logback 1.2 internal APIs directly See: https://github.com/spring-projects/spring-boot/issues/34708

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.