CVE-2023-6481

HIGH7.1EPSS 0.22%

Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data

Published: 12/4/2023Modified: 2/4/2026

Description

A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.1CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

References (6)