CVE-2017-5929
published 2017-03-13CVE-2017-5929: QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | logback | < logback 1:1.1.9-3 (bookworm) | logback 1:1.1.9-3 (bookworm) |
| qos | logback | < 1.2.0 | 1.2.0 |
| qos | logback | >= 0 < 1:1.1.9-3 | 1:1.1.9-3 |
| qos | logback | >= 0 < 1:1.1.9-3 | 1:1.1.9-3 |
| qos | logback | >= 0 < 1:1.1.9-3 | 1:1.1.9-3 |
| qos | logback | >= 0 < 1:1.1.9-3 | 1:1.1.9-3 |
| redhat | satellite | — | — |
| redhat | satellite_capsule | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL