logback-core是QOS.CH开源的一个日志框架的核心模块。 logback-core 1.5.32及之前版本存在安全漏洞,该漏洞源于HardenedObjectInputStream模块中反序列化不可信数据,可能导致对象注入,尽管受到严格限制,但能够影响发送到SimpleSocketServer或SimpleSSLSocketServer的序列化数据的攻击者可实例化java.lang和java.util包中未明确阻止的类对象,构成对预期安全限制的绕过。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| QOS.CH Sarl | logback | ≤ 1.5.32 |
affected |
1.5.33 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QOS.CH Sarl | logback | 0 ~ 1.5.32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet