fix(deps): update dependency ch.qos.logback:logback-core to v1.5.34 [security] - #29
Conversation
|
🚨 Stale Pull Request Warning This pull request has been inactive for 58 days. Automated Actions Schedule:
To keep this PR active:
Protected branches (won't be deleted): This is an automated message. Reply to this comment to reset the inactivity timer. |
d6a6ad6 to
97d9a10
Compare
🤖 AI Code Review
SummaryThis pull request updates the logback dependency from version 1.5.13 to 1.5.25 to address security vulnerabilities. The change is made in the Gradle build file for subprojects, ensuring the logging framework is patched against known security issues. Review Statistics
Critical Issues
None identified. Warnings
None identified. Suggestions
None identified. Positive Feedback
ℹ️ About this reviewThis review was automatically generated using the
|
|
🚨 Stale Pull Request Warning This pull request has been inactive for 33 days. Automated Actions Schedule:
To keep this PR active:
Protected branches (won't be deleted): This is an automated message. Reply to this comment to reset the inactivity timer. |
|
🚨 Stale Pull Request Warning This pull request has been inactive for 35 days. Automated Actions Schedule:
To keep this PR active:
Protected branches (won't be deleted): This is an automated message. Reply to this comment to reset the inactivity timer. |
PR Assist Bot — Owner Approval NeededThis PR targets release branch PR: AlaudaDevops/docker-sonarqube#29 Please reply with |
|
[pr-assist-bot] Release Branch Security PR — Owner Approval Needed This PR targets release branch PR: #29 — fix(deps): update dependency ch.qos.logback:logback-core to v1.5.25 [security] Please reply with |
PR Assist Bot AnalysisStatus: All CI checks passing, owner approval received ( |
|
🚨 Stale Pull Request Warning This pull request has been inactive for 34 days. Automated Actions Schedule:
To keep this PR active:
Protected branches (won't be deleted): This is an automated message. Reply to this comment to reset the inactivity timer. |
|
🚨 Stale Pull Request Warning This pull request has been inactive for 35 days. Automated Actions Schedule:
To keep this PR active:
Protected branches (won't be deleted): This is an automated message. Reply to this comment to reset the inactivity timer. |
97d9a10 to
049ff2b
Compare
049ff2b to
b0614ca
Compare
b0614ca to
aaf2a95
Compare
This PR contains the following updates:
1.5.13->1.5.34QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
CVE-2025-11226 / GHSA-25qh-j22f-pwp8
More information
Details
QOS.CH logback-core versions up to 1.5.18 contain an ACE vulnerability in conditional configuration file processing in Java applications. This vulnerability allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting a malicious environment variable before program execution.
A successful attack requires the Janino library and Spring Framework to be present on the user's class path. Additionally, the attacker must have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privileges.
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Logback allows an attacker to instantiate classes already present on the class path
CVE-2026-1225 / GHSA-qqpg-mvqg-649v
More information
Details
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.
The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.
Severity
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability
CVE-2026-9828 / GHSA-p47f-322f-whfh
More information
Details
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from classes in the java.lang and java.util packages that are not explicitly blocked.
Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions.
This issue affects logback: through 1.5.32 inclusive.
Severity
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:GreenReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
CVE-2026-10532 / GHSA-jhq6-gfmj-v8fx
More information
Details
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.
Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions.
This issue affects logback: through 1.5.33 inclusive.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:GreenReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.