Skip to content
This repository has been archived by the owner on Apr 23, 2024. It is now read-only.

Severe vulnerability requires logback version upgrade #49

Closed
cdanger opened this issue Jan 4, 2018 · 2 comments
Closed

Severe vulnerability requires logback version upgrade #49

cdanger opened this issue Jan 4, 2018 · 2 comments

Comments

@cdanger
Copy link

cdanger commented Jan 4, 2018

Hello,
logback News page says Release 1.2.0 fixes a rather severe serialization vulnerability in SocketServer and ServerSocketReceiver. Users running these components should upgrade immediately. Therefore, could you make a new release with logback.version >= 1.2.0 ?
It is 1.1.1 currently :-(

@cdanger
Copy link
Author

cdanger commented Jan 4, 2018

If you allow me as Contributor, I could do it. Maybe I would need some permission on Maven Central as well to publish the release.

@tony19
Copy link
Contributor

tony19 commented Feb 8, 2018

Fixed in 0.1.5

@tony19 tony19 closed this as completed Feb 8, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants