Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-5929 #183

Closed
DadoVio opened this issue Aug 6, 2018 · 2 comments
Closed

CVE-2017-5929 #183

DadoVio opened this issue Aug 6, 2018 · 2 comments
Milestone

Comments

@DadoVio
Copy link

DadoVio commented Aug 6, 2018

Hello,
using the plug-in org.owasp:dependency-check-gradle:3.3.0 in the android build script to found known vulnerability in the app and libraries, I found the CVE-2017-5929 vulnerability I guess inherited from the base QOS.ch Logback.
The main Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components, is it possible to update the main version?

@tony19
Copy link
Owner

tony19 commented Aug 6, 2018

This should be addressed in 1.2.0-1 (specifically by 13b2cd6).

The work to bring logback-android up to 1.3.0 is in progress.

@tony19 tony19 added this to the 1.2.0 milestone Aug 6, 2018
@tony19
Copy link
Owner

tony19 commented Sep 17, 2018

Fixed in v_1.2.0-1

@tony19 tony19 closed this as completed Sep 17, 2018
@github-actions github-actions bot locked and limited conversation to collaborators Nov 7, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants