A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
Solution:
Workaround:
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://logback.qos.ch/news.html#1.3.12 | release notes |
https://security.netapp.com/advisory/ntap-20241129-0012/ |