Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-15421

CVE-2017-5929 in 3.11.x (QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.)

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Urgent
    • Resolution: Duplicate
    • None
    • None
    • None
    • Security - Remote Code Execution
    • Critical
    • All
    • Security

    Description

      Description :Description : Severity : CVE CVSS 2.0: 7.5Sonatype CVSS 3: 9.8
       
       Weakness : CVE CWE: 502
       
       Source : National Vulnerability Database
       
       Categories : Data 
       Description from CVE : QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
       
       Explanation : The RemoteStreamAppenderClient class in logback-classic and the SocketNode classes in logback-classic and logback-access allow data to be deserialized over a Java Socket, via an ObjectInputStream, without validating the data beforehand.When data is received from the Socket, to be logged, it is deserialized into Java objects.An attacker can exploit this vulnerability by sending malicious, serialized Java objects over the connection to the Socket, which may result in execution of arbitrary code when those objects are deserialized.Note that although logback-core is implicated by the Logback project here, the Sonatype Security Research team discovered that the vulnerability is actually present in the logback-classic and logback-access components. versions prior to 1.2.0, as stated in the advisory. 
       Detection : The application is vulnerable by using this component. 
       Recommendation : We recommend upgrading to a version of this component that is not vulnerable to this specific issue. 
       Root Cause : apache-cassandra-3.11.4-bin.tar.gzch/qos/logback/classic/net/SocketNode.class : [1.0.12,1.2.0]
       
       Advisories : Project: https://logback.qos.ch/news.html
       
       CVSS Details : CVE CVSS 2.0: 7.5CVSS Vector: AV:N/AC:L/Au:N/C/I/A
      Occurences (Paths) : ["apache-cassandra.zip" ; "apache-cassandra.zip"]
      CVE : CVE-2017-5929
      URL : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5929
      Remediation : This component does not have any non-vulnerable Version. Please contact the vendor to get this vulnerability fixed.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              abhishek.scs Abhishek Singh
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: