CVE-2023-6481: Logback "receiver" DOS vulnerability CVE-2023-6378 incomplete fix
A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/ch.qos.logback:logback-coreto a version that resolves this vulnerability.Fixed in 1.2.13 - Upgrade
Upgrade
maven/ch.qos.logback:logback-coreto a version that resolves this vulnerability.Fixed in 1.3.14 - Upgrade
Upgrade
maven/ch.qos.logback:logback-coreto a version that resolves this vulnerability.Fixed in 1.4.14 - Upgrade
Upgrade
redhat/logback-classicto a version that resolves this vulnerability.Fixed in 1.2.13 - Upgrade
Upgrade
redhat/logback-classicto a version that resolves this vulnerability.Fixed in 1.3.14 - Upgrade
Upgrade
redhat/logback-classicto a version that resolves this vulnerability.Fixed in 1.4.14 - Upgrade
Upgrade
logbackto a version that resolves this vulnerability.Fixed in 1.4.14 - Upgrade
Upgrade
logbackto a version that resolves this vulnerability.Fixed in 1.3.14 - Upgrade
Upgrade
logbackto a version that resolves this vulnerability.Fixed in 1.2.13 - Configuration
If you do not need to deploy logback-receiver, verify that your logback configuration files do not contain any <receiver></receiver> entries.
logback receiver configuration <receiver> entries in configuration files = none - Compensating control
If logback receiver is deployed, restrict connections to the logback receiver so only trustworthy clients can connect (to mitigate the DoS risk from poisoned data).
Event History
Frequently Asked Questions
What is CVE-2023-6481?
CVE-2023-6481 is a vulnerability in the logback receiver component of logback versions 1.4.13, 1.3.13, and 1.2.12.
What is the severity of CVE-2023-6481?
CVE-2023-6481 has a severity rating of 7.1 (high).
How does CVE-2023-6481 work?
CVE-2023-6481 is a serialization vulnerability that allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Which software versions are affected by CVE-2023-6481?
CVE-2023-6481 affects logback versions 1.4.13, 1.3.13, and 1.2.12.
How can I fix CVE-2023-6481?
To fix CVE-2023-6481, update logback to a version that includes the complete fix, such as version 1.4.14 or higher.