QOS.CH SLF4J slf4j-ext模块代码问题漏洞

admin 2024-01-13 19:06:06 YS 来源:ZONE.CI 全球网 0 阅读模式
> QOS.CH SLF4J slf4j-ext模块代码问题漏洞

QOS.CH SLF4J slf4j-ext模块代码问题漏洞

CNNVD-ID编号 CNNVD-201803-708 CVE编号 CVE-2018-8088
发布时间 2018-03-21 更新时间 2021-02-01
漏洞类型 代码问题 漏洞来源 Chris McCown,Red Hat
危险等级 超危 威胁类型 远程
厂商 slf4j

漏洞介绍

QOS.CH SLF4J是瑞士QQS.CH公司的一款用于访问日志系统并查看日志文件的框架。slf4j-ext module是其中的一个扩展模块。

QOS.CH SLF4J 1.8.0-beta2之前版本中的slf4j-ext模块的org.slf4j.ext.EventData存在安全漏洞。远程攻击者可借助特制的数据利用该漏洞绕过访问限制。

漏洞补丁

目前厂商已发布升级了QOS.CH SLF4J slf4j-ext模块代码问题漏洞的补丁,QOS.CH SLF4J slf4j-ext模块代码问题漏洞的补丁获取链接:

参考网址

来源:BID

链接:http://www.securityfocus.com/bid/103737

来源:www.oracle.com

链接:https://www.oracle.com/technetwork/topics/security/linuxbulletinapr2018-4431087.html

来源:www.oracle.com

链接:https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

来源:www.slf4j.org

链接:https://www.slf4j.org/

来源:jira.qos.ch

链接:https://jira.qos.ch/browse/SLF4J-430

来源:access.redhat.com

链接:https://access.redhat.com/security/cve/cve-2018-8088

来源:bugzilla.redhat.com

链接:https://bugzilla.redhat.com/show_bug.cgi?id=1548909

来源:BID

链接:https://www.securityfocus.com/bid/103737

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:0592

来源:MLIST

链接:https://lists.apache.org/thread.html/95ce76613c869dbccf1d3d29327099ccc71aeec156f76c30853044fa@%3Cdevnull.infra.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:2413

来源:MISC

链接:https://www.oracle.com/security-alerts/cpuoct2020.html

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:2669

来源:MLIST

链接:https://lists.apache.org/thread.html/r81711cde77c2c5742b7b8533c978e79771b700af0ef4d3149d70df25@%3Cnotifications.logging.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1575

来源:MLIST

链接:https://lists.apache.org/thread.html/rfe52b7cbba4dcba521e13130e5d28d5818b78d70db0af1b470fa0264@%3Ccommon-issues.hadoop.apache.org%3E

来源:SECTRACK

链接:http://www.securitytracker.com/id/1040627

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:0628

来源:MISC

链接:https://github.com/qos-ch/slf4j/commit/d2b27fba88e983f921558da27fc29b5f5d269405

来源:MLIST

链接:https://lists.apache.org/thread.html/r1660c72a660f0522947ca6ce329dcc74e1ee20c58bbe208472754489@%3Ccommon-issues.hadoop.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rd86db9679150e9297b5c0fcb6f0e80a8b81b54fcf423de5a914bca78@%3Ccommon-commits.hadoop.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:0629

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:0627

来源:MISC

链接:https://jira.qos.ch/browse/SLF4J-431

来源:MLIST

链接:https://lists.apache.org/thread.html/reb3eeb985afdead17fadb7c33d5d472c1015a85ea5c9b038ec77f378@%3Ccommon-dev.hadoop.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:2420

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1450

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:0582

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1451

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:2143

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1251

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1449

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1249

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1447

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1448

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1525

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1247

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1248

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:2930

来源:MLIST

链接:https://lists.apache.org/thread.html/re6fb6b0de9d679310437ff87fc94e39da5a14dce9c73864a41837462@%3Ccommon-commits.hadoop.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:0630

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:1323

来源:MLIST

链接:https://lists.apache.org/thread.html/raabf1a00b2652575fca9fcb44166a828a0cab97a7d1594001eabc991@%3Ccommon-issues.hadoop.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/956ba8e76b6793a6670b2eb0129a5e3003ce2124ca3130fd57d48d0f@%3Cdevnull.infra.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:3140

来源:MLIST

链接:https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf@%3Ccommits.pulsar.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r767861f053c15f9e9201b939a0d508dd58475a072e76135eaaca17f0@%3Ccommon-issues.hadoop.apache.org%3E

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2018:2419

来源:MISC

链接:https://www.oracle.com/security-alerts/cpujul2020.html

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:2413

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:3140

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/153980/Red-Hat-Security-Advisory-2019-2413-01.html

来源:www.oracle.com

链接:https://www.oracle.com/security-alerts/cpuoct2020.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2071/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/154906/Red-Hat-Security-Advisory-2019-3140-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.3040/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.3899/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/158096/Red-Hat-Security-Advisory-2020-2561-01.html

受影响实体

Slf4j Slf4j:1.8.0:Alpha0 Slf4j Slf4j:1.8.0:Alpha1 Slf4j Slf4j:1.8.0:Alpha2 Slf4j Slf4j:1.8.0:Beta0 Slf4j Slf4j:1.8.0:Beta1

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201803-708

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0