CVE-2023-6378
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 29, 2023
Updated: Dec 5, 2023
CWE ID 502
Summary
CVE-2023-6378 is a new serialization vulnerability affecting the logback receiver component of logback version 1.4.11. This issue enables an attacker to execute a Denial-of-Service (DoS) attack by sending malicious data. By exploiting this weakness, an attacker can cause the targeted system to crash, leading to service disruption. The root cause of the vulnerability is not yet disclosed, but users are strongly advised to upgrade to the latest logback version or apply the provided mitigation measures to protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- QoS