First published: Mon Mar 26 2018(Updated: )
The Simple Logging Facade for Java or (SLF4J) is a simple facade for various logging APIs allowing the end-user to plug in the desired implementation at deployment time. SLF4J also allows for a gradual migration path away from Jakarta Commons Logging (JCL).<br>Security Fix(es):<br><li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Chris McCown for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-maven35-slf4j | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-jcl-over-slf4j | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-jul-to-slf4j | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-log4j-over-slf4j | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-ext | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-javadoc | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-jcl | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-jdk14 | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-log4j12 | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-manual | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
redhat/rh-maven35-slf4j-sources | <1.7.25-1.3.el7 | 1.7.25-1.3.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.