jboss-logmanager is vulnerable to Uncontrolled Recursion
43
Medium Risk
Affected versions of this package are vulnerable to a reentrancy issue in asynchronous logging methods that could lead to a stack overflow. This vulnerability arises when asynchronous logging methods lack proper locking checks, allowing reentrant calls that can recursively exhaust the call stack. An attacker might exploit this by crafting log events that trigger recursive logging, causing a stack overflow and resulting in a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
jboss-logmanager is vulnerable to Uncontrolled Recursion in versions 3.0.3.Final - 3.1.2.Final.
Upgrade the org.jboss.logmanager:jboss-logmanager library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant