mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-30 18:20:53 +00:00
24 lines
1.1 KiB
Markdown
24 lines
1.1 KiB
Markdown
![]() |
### [CVE-2018-8088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8088)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://www.oracle.com/security-alerts/cpujul2020.html
|
||
|
- https://www.oracle.com/security-alerts/cpuoct2020.html
|
||
|
- https://www.oracle.com/security-alerts/cpuoct2021.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/Dzmitry-Basiachenka/dist-foreign-aliakh
|
||
|
- https://github.com/aaronm-sysdig/risk-accept
|
||
|
- https://github.com/aaronm-sysdig/risk-reset
|
||
|
- https://github.com/aikebah/DC-issue1444-demo
|
||
|
|