papertrail / logback-syslog4j

Logback appender for syslog4j
MIT License
0 stars 1 forks source link

Arbitrary code execution vulnerability #20

Open karthik-phl opened 3 years ago

karthik-phl commented 3 years ago

Hi, Snyk advices that there is an Arbitrary Code Execution vulnerability in logback-syslog4j introduced through "ch.qos.logback:logback-classic@1.1.2" and "ch.qos.logback:logback-core@1.1.2". Are there any plans of upgrading ch.qos.logback version to 1.2.0? Thanks.