HIGH 7.1 Maven

logback serialization vulnerability

GHSA-vmq6-5m68-f53m · CVE-2023-6378

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html

Ready to move

Start Securing

Free, no credit card | First findings in minutes