CVE-2023-6378
published 2023-11-29CVE-2023-6378: A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.90%
55.7th percentile
A serialization vulnerability in logback receiver component part of
logback version 1.4.11 allows an attacker to mount a Denial-Of-Service
attack by sending poisoned data.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | bitbucket_data_center | — | — |
| debian | logback | < logback 1:1.2.11-5 (forky) | logback 1:1.2.11-5 (forky) |
| qos | logback | >= 0 < 1:1.2.11-5 | 1:1.2.11-5 |
| qos | logback | >= 0 < 1:1.2.11-5 | 1:1.2.11-5 |
| qos | logback | >= 0 < 1:1.1.3-2ubuntu0.1~esm1 | 1:1.1.3-2ubuntu0.1~esm1 |
| qos | logback | >= 0 < 1:1.2.3-2ubuntu1~18.04.1+esm1 | 1:1.2.3-2ubuntu1~18.04.1+esm1 |
| qos | logback | >= 0 < 1:1.2.3-5ubuntu0.1~esm1 | 1:1.2.3-5ubuntu0.1~esm1 |
| qos | logback | >= 0 < 1:1.2.10-1ubuntu0.1~esm1 | 1:1.2.10-1ubuntu0.1~esm1 |
| qos | logback | >= 1.2.0 < 1.2.13 | 1.2.13 |
| qos | logback | >= 1.3.0 < 1.3.12 | 1.3.12 |
| qos | logback | >= 1.4.0 < 1.4.12 | 1.4.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_oracle7.5HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
logback vulnerabilities
osv·2025-07-02·CVSS 6.6
CVE-2021-42550 [MEDIUM] logback vulnerabilities
logback vulnerabilities
It was discovered that logback could read malicious configuration files
from LDAP servers. An attacker with the required permissions could possibly
use this issue to execute arbitrary code. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-42550) It was
discovered that logback contained a serialization vulnerability. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-6378)
OSV
logback serialization vulnerability
osv·2023-11-29
CVE-2023-6378 [HIGH] logback serialization vulnerability
logback serialization vulnerability
A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html
GHSA
logback serialization vulnerability
ghsa·2023-11-29
CVE-2023-6378 [HIGH] CWE-502 logback serialization vulnerability
logback serialization vulnerability
A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html
OSV
CVE-2023-6378: A serialization vulnerability in logback receiver component part of logback version 1
osv·2023-11-29·CVSS 7.5
CVE-2023-6378 [HIGH] CVE-2023-6378: A serialization vulnerability in logback receiver component part of logback version 1
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
OSV
python-django vulnerabilities
osv·2023-10-04·CVSS 7.5
CVE-2023-43665 python-django vulnerabilities
python-django vulnerabilities
USN-6414-1 and USN-6378-1 fixed CVE-2023-43665 and CVE-2023-41164 in Django,
respectively. This update provides the corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
Wenchao Li discovered that the Django Truncator function incorrectly
handled very long HTML input. A remote attacker could possibly use this
issue to cause Django to consume resources, leading to a denial of service.
It was discovered that Django incorrectly handled certain URIs with a very
large number of Unicode characters. A remote attacker could possibly use
this issue to cause Django to consume resources or crash, leading to a
denial of service.
CISA ICS
Hitachi Energy Asset Suite
cisa_ics·2025-09-18·CVSS 7.1
[HIGH] Hitachi Energy Asset Suite
ICS Advisory
##
Hitachi Energy Asset Suite
Release DateSeptember 18, 2025
Alert CodeICSA-25-261-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Asset Suite
- Vulnerabilities: Server-Side Request Forgery (SSRF), Deserialization of Untrusted Data, Cleartext Storage of Sensitive Information, Uncontrolled Resource Consumption, URL Redirection to Untrusted Site ('Open Redirect'), Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow attackers to trigger resource consumption or information disclosure through SSRF in Apache XML Gra
Ubuntu
logback vulnerabilities
vendor_ubuntu·2025-07-02·CVSS 6.6
CVE-2023-6378 [MEDIUM] logback vulnerabilities
Title: logback vulnerabilities
Summary: Several security issues were fixed in logback.
It was discovered that logback could read malicious configuration files
from LDAP servers. An attacker with the required permissions could possibly
use this issue to execute arbitrary code. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-42550) It was
discovered that logback contained a serialization vulnerability. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-6378)
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Oracle
Oracle Oracle Communications Applications Risk Matrix: Patch (logback) — CVE-2023-6378
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-6378 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Patch (logback) — CVE-2023-6378
Oracle Oracle Communications Applications Risk Matrix: Patch (logback) vulnerability
CVE: CVE-2023-6378
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Atlassian
CVE-2023-6378: DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
vendor_atlassian·2024-01-16·CVSS 7.5
CVE-2023-6378 [HIGH] CVE-2023-6378: DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
CVE-2023-6378: DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
CVE: CVE-2023-6378
Severity: HIGH
Affected products: Bitbucket Data Center
Red Hat
logback: serialization vulnerability in logback receiver
vendor_redhat·2023-11-29·CVSS 7.1
CVE-2023-6378 [HIGH] CWE-499 logback: serialization vulnerability in logback receiver
logback: serialization vulnerability in logback receiver
A serialization vulnerability in logback receiver component part of
logback version 1.4.11 allows an attacker to mount a Denial-Of-Service
attack by sending poisoned data.
A flaw was found in the logback package, where it is vulnerable to a denial of service caused by a serialization flaw in the receiver component. By sending specially crafted poisoned data, a remote attacker can cause a denial of service condition.
Statement: The Logback package vulnerability, posing a risk of denial-of-service through a serialization flaw in its receiver component, is considered a moderate issue due to its potential impact on system availability. While denial-of-service vulnerabilities can be disruptive, the severity is tempered by the fact that
Debian
CVE-2023-6378: logback - A serialization vulnerability in logback receiver component part of logback ver...
vendor_debian·2023·CVSS 7.1
CVE-2023-6378 [HIGH] CVE-2023-6378: logback - A serialization vulnerability in logback receiver component part of logback ver...
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.2.11-5)
sid: resolved (fixed in 1:1.2.11-5)
trixie: resolved (fixed in 1:1.2.11-5)
No detection rules found.
No public exploits indexed.
2023-11-29
Published