Affected packages
- ch.qos.logback:logback-classic— 1.3.0 → 1.3.12
- ch.qos.logback:logback-core— 1.3.0 → 1.3.12
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2023-6378
- https://github.com/qos-ch/logback/issues/745#issuecomment-1836227158
- https://github.com/qos-ch/logback/commit/9c782b45be4abdafb7e17481e24e7354c2acd1eb
- https://github.com/qos-ch/logback/commit/b8eac23a9de9e05fb6d51160b3f46acd91af9731
- https://github.com/qos-ch/logback/commit/bb095154be011267b64e37a1d401546e7cc2b7c3
- https://github.com/qos-ch/logback
- https://logback.qos.ch/manual/receivers.html
- https://logback.qos.ch/news.html#1.2.13
- https://logback.qos.ch/news.html#1.3.12
- https://security.netapp.com/advisory/ntap-20241129-0012
Structured record: https://osv.dev/vulnerability/GHSA-vmq6-5m68-f53m
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta