CVE-2017-5929: Qos Logback

Critical severity, CVSS 9.8. EPSS: 7.5% chance of exploitation in the next 30 days.

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Affected products

  • Qos Logback: before 1.2.0 (fixed in 1.2.0)
  • Red Hat Satellite: version 6.4 only
  • Red Hat Satellite Capsule: version 6.4 only

Published 2017-03-13. Last modified 2026-06-17.