Uploaded image for project: 'Apache Arrow'
  1. Apache Arrow
  2. ARROW-1240

security: upgrade logback to address CVE-2017-5929

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 0.4.1
    • 0.6.0
    • Java
    • None

    Description

      logback versions before 1.2.0 are affected by "a rather severe serialization vulnerability in SocketServer and ServerSocketReceiver".

      We should upgrade logback from 1.0.13 to the latest version (currently 1.2.3) in order to address this.

      See https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5929
      and
      https://logback.qos.ch/news.html

      Attachments

        Activity

          People

            mdarwin Matt Darwin
            mdarwin Matt Darwin
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: