Back

CVE-2017-5929

CRITICAL

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Published: Mar 13, 2017 Modified: Jun 17, 2026
CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
qos logback * < 1.2.0
redhat satellite 6.4
redhat satellite_capsule 6.4

GitHub Security Advisory GHSA-vmfg-rjjm-rjrj

QOS.ch Logback vulnerable to Deserialization of Untrusted Data

maven ch.qos.logback:logback-classic < 1.2.0 Fixed: 1.2.0
maven ch.qos.logback:logback-core < 1.2.0 Fixed: 1.2.0

References (42)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 7.50%

Top 6% most likely to be exploited

Threat Score 41.5 / 100

Data Sources

NVD EPSS GitHub