First published: Mon Mar 26 2018(Updated: )
The Simple Logging Facade for Java or (SLF4J) is a simple facade for various logging APIs allowing the end-user to plug in the desired implementation at deployment time. SLF4J also allows for a gradual migration path away from Jakarta Commons Logging (JCL).<br>Security Fix(es):<br><li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Chris McCown for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/slf4j | <1.7.4-4.el7_4 | 1.7.4-4.el7_4 |
redhat/slf4j | <1.7.4-4.el7_4 | 1.7.4-4.el7_4 |
redhat/slf4j-javadoc | <1.7.4-4.el7_4 | 1.7.4-4.el7_4 |
redhat/slf4j-manual | <1.7.4-4.el7_4 | 1.7.4-4.el7_4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.