{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "serialization vulnerability in logback receiver",
    "tracking": {
      "current_release_date": "2026-07-25T10:17:58+00:00",
      "generator": {
        "date": "2026-07-25T10:17:58+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2023-6378",
      "initial_release_date": "2023-11-29T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-25T10:17:58+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Migration Toolkit for Applications MTA 6.2.0",
            "product": {
              "name": "Migration Toolkit for Applications MTA 6.2.0",
              "product_id": "mta-6",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:migration_toolkit_applications:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Migration Toolkit for Applications MTA 7.3.0",
            "product": {
              "name": "Migration Toolkit for Applications MTA 7.3.0",
              "product_id": "mta-7",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Migration Toolkit for Runtimes MTR-1.2.0",
            "product": {
              "name": "Migration Toolkit for Runtimes MTR-1.2.0",
              "product_id": "mtr-1.2",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:migration_toolkit_runtimes:1"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform Logging 5.9.z",
            "product": {
              "name": "OpenShift Container Platform Logging 5.9.z",
              "product_id": "openshift-logging-5",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:logging:5"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat OpenShift Dev Spaces 3.28.0.GA",
            "product": {
              "name": "Red Hat OpenShift Dev Spaces 3.28.0.GA",
              "product_id": "rhos_devspaces-3::el8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift_devspaces:3::el8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "devspaces/server-rhel8",
            "product": {
              "name": "devspaces/server-rhel8",
              "product_id": "devspaces/server-rhel8-0:3.15-3",
              "product_identification_helper": {
                "purl": "pkg:oci/server-rhel8@3.15-3?repository_url=registry.redhat.io/devspaces/server-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "logback",
            "product": {
              "name": "logback",
              "product_id": "logback.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/logback?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift-logging/elasticsearch6-rhel8",
            "product": {
              "name": "openshift-logging/elasticsearch6-rhel8",
              "product_id": "openshift-logging/elasticsearch6-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/elasticsearch6-rhel8?repository_url=registry.redhat.io/openshift-logging/elasticsearch6-rhel8"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "devspaces/server-rhel8-0:3.15-3 as a component of Red Hat OpenShift Dev Spaces 3.28.0.GA",
          "product_id": "rhos_devspaces-3::el8:devspaces/server-rhel8-0:3.15-3"
        },
        "product_reference": "devspaces/server-rhel8-0:3.15-3",
        "relates_to_product_reference": "rhos_devspaces-3::el8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "logback.src as a component of Migration Toolkit for Applications MTA 6.2.0",
          "product_id": "mta-6:logback.src"
        },
        "product_reference": "logback.src",
        "relates_to_product_reference": "mta-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "logback.src as a component of Migration Toolkit for Runtimes MTR-1.2.0",
          "product_id": "mtr-1.2:logback.src"
        },
        "product_reference": "logback.src",
        "relates_to_product_reference": "mtr-1.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "logback.src as a component of Migration Toolkit for Applications MTA 7.3.0",
          "product_id": "mta-7:logback.src"
        },
        "product_reference": "logback.src",
        "relates_to_product_reference": "mta-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift-logging/elasticsearch6-rhel8 as a component of OpenShift Container Platform Logging 5.9.z",
          "product_id": "openshift-logging-5:openshift-logging/elasticsearch6-rhel8"
        },
        "product_reference": "openshift-logging/elasticsearch6-rhel8",
        "relates_to_product_reference": "openshift-logging-5"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-6378",
      "cwe": {
        "id": "CWE-499",
        "name": "Serializable Class Containing Sensitive Data"
      },
      "discovery_date": "2023-11-30T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "mtr-1.2:logback.src",
            "openshift-logging-5:openshift-logging/elasticsearch6-rhel8"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "The Logback package vulnerability, posing a risk of denial-of-service through a serialization flaw in its receiver component, is considered a moderate issue due to its potential impact on system availability. While denial-of-service vulnerabilities can be disruptive, the severity is tempered by the fact that they generally do not result in unauthorized access or data compromise.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A flaw was found in the logback package, where it is vulnerable to a denial of service caused by a serialization flaw in the receiver component. By sending specially crafted poisoned data, a remote attacker can cause a denial of service condition.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "rhos_devspaces-3::el8:devspaces/server-rhel8-0:3.15-3"
        ],
        "known_affected": [
          "mta-6:logback.src",
          "mta-7:logback.src"
        ],
        "known_not_affected": [
          "mtr-1.2:logback.src",
          "openshift-logging-5:openshift-logging/elasticsearch6-rhel8"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-6378"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6378"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-6378"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "mta-6:logback.src"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "mta-7:logback.src"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2024-07-18T17:11:22+00:00",
          "details": "Apply advisory RHSA-2024:4631 as per vendors instructions.",
          "product_ids": [
            "rhos_devspaces-3::el8:devspaces/server-rhel8-0:3.15-3"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2024:4631"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
          "product_ids": [
            "mta-6:logback.src",
            "mta-7:logback.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "mta-6:logback.src",
            "mta-7:logback.src",
            "mtr-1.2:logback.src",
            "openshift-logging-5:openshift-logging/elasticsearch6-rhel8",
            "rhos_devspaces-3::el8:devspaces/server-rhel8-0:3.15-3"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "mta-6:logback.src",
            "mta-7:logback.src",
            "mtr-1.2:logback.src",
            "openshift-logging-5:openshift-logging/elasticsearch6-rhel8",
            "rhos_devspaces-3::el8:devspaces/server-rhel8-0:3.15-3"
          ]
        }
      ],
      "title": "serialization vulnerability in logback receiver"
    }
  ]
}