jboss-logmanager is vulnerable to Uncontrolled Recursion
43
Medium Risk
Affected versions of this package are vulnerable to a reentrancy issue in asynchronous logging methods that could lead to a stack overflow. This vulnerability arises when asynchronous logging methods lack proper locking checks, allowing reentrant calls that can recursively exhaust the call stack. An attacker might exploit this by crafting log events that trigger recursive logging, causing a stack overflow and resulting in a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
jboss-logmanager is vulnerable to Uncontrolled Recursion in versions 3.0.3.Final - 3.1.2.Final.
Upgrade the org.jboss.logmanager:jboss-logmanager library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant