CVE-2017-5929

Severity
9.8CRITICAL
EPSS
10.1%
top 6.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateOct 18

Description

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDqos/logback< 1.2.0
Debianlogback< 1:1.1.9-3+3

🔴Vulnerability Details

4
OSV
QOS.ch Logback vulnerable to Deserialization of Untrusted Data2021-06-07
GHSA
QOS.ch Logback vulnerable to Deserialization of Untrusted Data2021-06-07
OSV
CVE-2017-5929: QOS2017-03-13
CVEList
CVE-2017-5929: QOS2017-03-13

📋Vendor Advisories

2
Red Hat
logback: Serialization vulnerability in SocketServer and ServerSocketReceiver2017-02-08
Debian
CVE-2017-5929: logback - QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the Sock...2017

💬Community

3
HackerOne
CVE-2017-5929: Hyperledger - Arbitrary Deserialization of Untrusted Data2022-10-18
HackerOne
2 vulnerabilities of arbitrary code in ████████ - CVE-2017-59292019-10-08
Bugzilla
CVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiver2017-03-16