exasol / cloud-storage-extension

Exasol Cloud Storage Extension for accessing formatted data Avro, Orc and Parquet, on public cloud storage systems
MIT License
7 stars 11 forks source link

🔐 CVE-2023-6378: pkg:maven/ch.qos.logback/logback-core@1.2.10 #288

Closed github-actions[bot] closed 10 months ago

github-actions[bot] commented 10 months ago

Summary

A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

CVE: CVE-2023-6378 CWE: CWE-502

References

ckunki commented 10 months ago

Approved PR #292 (vulnerabilities)

ckunki commented 10 months ago

And approved PR #291 (tests with many files)