logback serialization vulnerability #240
Labels
agent-java
community
Issues and PRs created by the community
triage
Issues and PRs that need to be triaged
Upgrade ch.qos.logback:logback-classic to fix 2 Dependabot alerts in logback-legacy-tests/pom.xml
Upgrade ch.qos.logback:logback-classic to version 1.2.13 or later. For example:
A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html
The text was updated successfully, but these errors were encountered: