Back
CVE-2017-5929
CRITICAL
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
Published: Mar 13, 2017
Modified: Jun 17, 2026
CWE-502
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| qos | logback | * < 1.2.0 |
| redhat | satellite | 6.4 |
| redhat | satellite_capsule | 6.4 |
GitHub Security Advisory GHSA-vmfg-rjjm-rjrj
QOS.ch Logback vulnerable to Deserialization of Untrusted Data
maven
ch.qos.logback:logback-classic
< 1.2.0
Fixed: 1.2.0
maven
ch.qos.logback:logback-core
< 1.2.0
Fixed: 1.2.0
References (42)
- https://access.redhat.com/errata/RHSA-2017:1675 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1676 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1832 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2927 Third Party Advisory
- https://lists.apache.org/thread.html/18d509024d9aeb07f0e9579066f80bf5d4dcf20467b0c240043890d1%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/a6db61616180d73711d6db25703085940026e2dbc40f153f9d22b203%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/fa4eaaa6ff41ac6f79811e053c152ee89b7c5da8a6ac848ae97df67f%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r0bb19330e48d5ad784fa20dacba9e5538d8d60f5cd9142e0f1432b4b%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r2a08573ddee4a86dc96d469485a5843a01710ee0dc2078dfca410c79%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r2c2d57ca180e8173c90fe313ddf8eabbdcf8e3ae196f8b9f42599790%40%3Ccommits.mnemonic.apache.org%3E
- https://lists.apache.org/thread.html/r397bf63783240fbb5713389d3f889d287ae0c11509006700ac720037%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r4673642893562c58cbee60c151ded6c077e8a2d02296e862224a9161%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r632ec30791b441e2eb5a3129532bf1b689bf181d0ef7daf50bcf0fd6%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r718f27bed898008a8e037d9cc848cfc1df4d18abcbaee0cb0c142cfb%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/r967953a14e05016bc4bcae9ef3dd92e770181158b4246976ed8295c9%40%3Cdev.brooklyn.apache.org%3E
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
7.50%
Top 6% most likely to be exploited
Threat Score
41.5 / 100
Data Sources
NVD
EPSS
GitHub