| 概要 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to Although deserialization is heavily restricted by HardenedObjectInputStream and no This issue affects logback: through 1.5.33 inclusive. |
|---|---|
| 公表日 | 2026年6月1日22:16 |
| 登録日 | 2026年6月2日4:17 |
| 最終更新日 | 2026年6月2日3:16 |