Uploaded image for project: 'TinkerPop'
  1. TinkerPop
  2. TINKERPOP-3050

security vulnerability in logback-core

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • 3.6.6
    • 3.6.8, 3.7.3
    • console
    • None

    Description

      used logback-core version is: 1.2.11- CVE-2023-6378

      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6378

       

      https://github.com/advisories/GHSA-vmq6-5m68-f53m

      I see that even latest v1.2.13 has security issue: 

      https://mvnrepository.com/artifact/ch.qos.logback/logback-core

      1.3.12, 1.3.14, 1.4.12 and latest 1.4.14 are currently safe

       

      Attachments

        Activity

          People

            colegreer Cole Greer
            talron Tal Ron
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: