CVE Vulnerabilities

CVE-2023-6481

Published: Dec 04, 2023 | Modified: Dec 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

Affected Software

Name Vendor Start Version End Version
Logback Qos 1.2.12 (including) 1.2.12 (including)
Logback Qos 1.3.13 (including) 1.3.13 (including)
Logback Qos 1.4.13 (including) 1.4.13 (including)
Red Hat AMQ Broker 7 RedHat logback *
Red Hat Fuse 7.13.0 RedHat logback *
RHINT Camel-Springboot 4.0.3 RedHat logback *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/client-kn-rhel8:1.10.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-istio-controller-rhel8:1.10.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-controller-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-post-install-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-receiver-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-webhook-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-filter-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-ingress-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtchannel-broker-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtping-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-storage-version-migration-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/func-utils-rhel8:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/ingress-rhel8-operator:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/knative-rhel8-operator:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/kn-cli-artifacts-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/kourier-control-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/net-istio-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/net-istio-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serverless-operator-bundle:1.31.1-1 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serverless-rhel8-operator:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-activator-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-hpa-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-domain-mapping-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-domain-mapping-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-queue-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-storage-version-migration-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/svls-must-gather-rhel8:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/eventing-istio-controller-rhel8:1.10.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/logic-swf-builder-rhel8:1.31.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8:1.31.0-4 *
RHPAM 7.13.5 async RedHat *
Logback Ubuntu bionic *
Logback Ubuntu lunar *
Logback Ubuntu mantic *
Logback Ubuntu trusty *
Logback Ubuntu xenial *

References