logback-core is vulnerable to Improper Input Validation
59
Medium Risk
Affected versions of this package do not properly validate the logback.xml configuration file when both the Janino library and the Spring Framework are present on the classpath. An attacker can execute arbitrary code by compromising an existing configuration file or injecting a malicious environment variable prior to program execution. This vulnerability is exploitable only if the attacker has write access to a configuration file or the ability to set malicious environment variables.
You are affected if you are using a version that falls within the vulnerable range and both the Janino library and the Spring Framework are present on the classpath.
logback-core is vulnerable to Improper Input Validation in versions 1.4.0 - 1.5.18 and 0.9.20 - 1.3.15.
Upgrade the ch.qos.logback:logback-core library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant