cbcvebase.
CVE-2018-8088
published 2018-03-20

CVE-2018-8088: org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibslf4j-java< libslf4j-java 1.7.25-3 (bookworm)libslf4j-java 1.7.25-3 (bookworm)
oraclegoldengate_application_adapters
oraclegoldengate_stream_analytics< 19.1.0.0.119.1.0.0.1
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
qosslf4j< 1.7.261.7.26
qosslf4j
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL