CVE-2023-6481
published 2023-12-04CVE-2023-6481: A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.68%
48.5th percentile
A serialization vulnerability in logback receiver component part of
logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service
attack by sending poisoned data.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | bitbucket_data_center | — | — |
| debian | logback | — | — |
| qos | logback | — | — |
| qos | logback | — | — |
| qos | logback | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Atlassian
CVE-2023-6481: DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
vendor_atlassian·2024-01-16·CVSS 7.5
CVE-2023-6481 [HIGH] CVE-2023-6481: DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
CVE-2023-6481: DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server
CVE: CVE-2023-6481
Severity: HIGH
Affected products: Bitbucket Data Center
Red Hat
logback: A serialization vulnerability in logback receiver
vendor_redhat·2023-12-04·CVSS 7.1
CVE-2023-6481 [HIGH] CWE-400 logback: A serialization vulnerability in logback receiver
logback: A serialization vulnerability in logback receiver
A serialization vulnerability in logback receiver component part of
logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service
attack by sending poisoned data.
A flaw was found in the logback package. Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') via the logback receiver component. This flaw allows an attacker to mount a denial-of-service attack by sending poisoned data.
Statement: The security vulnerability in the logback package is considered of moderate severity due to its potential for facilitating a denial-of-service (DoS) attack. While a DoS attack can disrupt service availability, this vulnerability may not lead to more severe c
Debian
CVE-2023-6481: logback - A serialization vulnerability in logback receiver component part of logback ver...
vendor_debian·2023·CVSS 7.1
CVE-2023-6481 [HIGH] CVE-2023-6481: logback - A serialization vulnerability in logback receiver component part of logback ver...
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
osv·2023-12-04
CVE-2023-6481 [HIGH] Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
GHSA
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
ghsa·2023-12-04
CVE-2023-6481 [HIGH] Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
OSV
CVE-2023-6481: A serialization vulnerability in logback receiver component part of logback version 1
osv·2023-12-04·CVSS 7.5
CVE-2023-6481 [HIGH] CVE-2023-6481: A serialization vulnerability in logback receiver component part of logback version 1
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
No detection rules found.
No public exploits indexed.
2023-12-04
Published