Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update logback to 1.2.0 or later #2182

Closed
msymons opened this issue Apr 26, 2017 · 0 comments
Closed

Update logback to 1.2.0 or later #2182

msymons opened this issue Apr 26, 2017 · 0 comments
Milestone

Comments

@msymons
Copy link
Contributor

msymons commented Apr 26, 2017

Update QOS.ch Logback to 1.2.0 or later in order to address threat CVE-2017-5929 with CVSS v3 Base Score 9.8.

From Logback News:

Release 1.2.0 fixes a rather severe serialization vulnerability in SocketServer and ServerSocketReceiver. Users running these components should upgrade immediately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants