Skip to content

Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] - #77

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/maven-ch.qos.logback-logback-classic-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/maven-ch.qos.logback-logback-classic-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Nov 30, 2023

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ch.qos.logback:logback-classic (source, changelog) 1.2.121.2.13 age confidence

logback serialization vulnerability

CVE-2023-6378 / GHSA-vmq6-5m68-f53m

More information

Details

A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

This is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html

Severity

  • CVSS Score: 7.1 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Nov 30, 2023

Copy link
Copy Markdown

Unit Test Results

144 177 tests  ±0   144 177 ✔️ ±0   2m 4s ⏱️ ±0s
         24 suites ±0              0 💤 ±0 
         24 files   ±0              0 ±0 

Results for commit 355e56b. ± Comparison against base commit 133acbf.

♻️ This comment has been updated with latest results.

@renovate renovate Bot changed the title Update dependency ch.qos.logback:logback-classic to v1.3.12 [SECURITY] Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] Dec 5, 2023
@renovate
renovate Bot force-pushed the renovate/maven-ch.qos.logback-logback-classic-vulnerability branch from 759c0bf to 0b5f47d Compare December 5, 2023 23:00
@renovate
renovate Bot force-pushed the renovate/maven-ch.qos.logback-logback-classic-vulnerability branch from 0b5f47d to 951308e Compare October 21, 2025 09:49
@renovate
renovate Bot force-pushed the renovate/maven-ch.qos.logback-logback-classic-vulnerability branch from 951308e to 60aa37a Compare November 11, 2025 02:32
@renovate renovate Bot changed the title Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/maven-ch.qos.logback-logback-classic-vulnerability branch March 27, 2026 00:57
@renovate renovate Bot changed the title Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] - autoclosed Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/maven-ch.qos.logback-logback-classic-vulnerability branch 2 times, most recently from 60aa37a to 7518255 Compare March 30, 2026 20:42
@renovate renovate Bot changed the title Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] - autoclosed Update dependency ch.qos.logback:logback-classic to v1.2.13 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/maven-ch.qos.logback-logback-classic-vulnerability branch 2 times, most recently from 7518255 to 355e56b Compare April 27, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants