PT-2026-44381 · Logback · Logback
CVSS v4.0
2.9
Low
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:Green |
Name of the Vulnerable Software and Affected Versions
logback versions prior to 1.5.33
Description
Deserialization of untrusted data in the
HardenedObjectInputStream module of logback-core allows for restricted Object Injection. An attacker capable of influencing serialized data sent to the 'SimpleSocketServer' or 'SimpleSSLSocketServer' endpoints can instantiate objects from the java.lang and java.util packages that are not explicitly blocked. This issue represents a bypass of intended security restrictions, although no practical method for remote code execution or significant privilege escalation has been identified.Recommendations
Update to a version later than 1.5.32.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logback