MGASA-2019-0079

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 14 Feb 2019, 08:38
Last modified:16 Apr 2026, 06:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Feb 2019, 08:38
Published
Vulnerability first disclosed
16 Apr 2026, 06:26
Last Modified
Vulnerability information updated

Description

Updated logback packages fix security vulnerability It was found that logback is vulnerable to a deserialization issue. Logback can be configured to allow remote logging through SocketServer/ServerSocketReceiver interfaces that can accept untrusted serialized data. Authenticated attackers on the adjacent network can leverage this vulnerability to execute arbitrary code through deserialization of custom gadget chains (CVE-2017-5929).

Affected Systems

  • mageialogback

    < 1.1.3-2.1.mga6

References (3)