Improper Access Control in SLF4J
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Dec 29, 2023
Package
Affected versions
<= 1.7.25
>= 1.8.0-alpha0, <= 1.8.0-beta2
Patched versions
1.7.26
1.8.0-beta4
Description
Published by the National Vulnerability Database
Mar 20, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 29, 2022
Last updated
Dec 29, 2023
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before
1.8.0-beta4
allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J version1.7.26
and later and in the2.0.x
series.Note that while the fix commit is associated with the tag
1.8.0-beta3
, the versions in Maven go directly from1.8.0-beta2
to1.8.0-beta4
.References