« Volver al listado

CVE-2023-6378

Estado: ModificadaAlta (7.5)—

A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6378",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6378",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-11T17:51:31.895829Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vulnerability@ncsc.ch",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@ncsc.ch",
      "affectedData": [
        {
          "repo": "https://github.com/qos-ch/logback",
          "vendor": "QOS.CH Sarl",
          "modules": [
            "logback receiver"
          ],
          "product": "logback",
          "versions": [
            {
              "status": "unaffected",
              "version": "1.4.12"
            },
            {
              "status": "unaffected",
              "version": "1.3.12"
            },
            {
              "status": "unaffected",
              "version": "1.2.13"
            }
          ],
          "platforms": [
            "Windows",
            "Linux",
            "MacOS"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-29T12:15:07.543",
  "references": [
    {
      "url": "https://logback.qos.ch/news.html#1.3.12",
      "tags": [
        "Release Notes"
      ],
      "source": "vulnerability@ncsc.ch"
    },
    {
      "url": "https://logback.qos.ch/news.html#1.3.12",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20241129-0012/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A serialization vulnerability in logback receiver component part of \nlogback version 1.4.11 allows an attacker to mount a Denial-Of-Service \nattack by sending poisoned data.\n\n"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de serialización en el componente receptor de inicio de sesión de la versión 1.4.11 permite a un atacante montar un ataque de Denegación de Servicio mediante el envío de datos envenenados."
    }
  ],
  "lastModified": "2026-06-17T06:50:38.650",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qos:logback:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A75DA21-E526-4DD5-A438-AF8420D862A2",
              "versionEndExcluding": "1.2.13",
              "versionStartIncluding": "1.2.0"
            },
            {
              "criteria": "cpe:2.3:a:qos:logback:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C85D3836-AB90-468C-8C38-528FF62C3595",
              "versionEndExcluding": "1.3.12",
              "versionStartIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:qos:logback:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF67A816-FE60-4301-AA46-EED6E5F5AC66",
              "versionEndExcluding": "1.4.12",
              "versionStartIncluding": "1.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerability@ncsc.ch"
}