org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Slf4j | Qos | * | 1.7.26 (excluding) |
Slf4j | Qos | 1.8.0-alpha1 (including) | 1.8.0-alpha1 (including) |
Slf4j | Qos | 1.8.0-alpha2 (including) | 1.8.0-alpha2 (including) |
Slf4j | Qos | 1.8.0-beta1 (including) | 1.8.0-beta1 (including) |
Slf4j | Qos | 1.8.0-beta2 (including) | 1.8.0-beta2 (including) |