Skip to content

[Aikido] Fix 4 security issues in ch.qos.logback:logback-core, ch.qos.logback:logback-classic, org.json:json#69

Closed
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-update-packages-10058157-mt7Q
Closed

[Aikido] Fix 4 security issues in ch.qos.logback:logback-core, ch.qos.logback:logback-classic, org.json:json#69
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-update-packages-10058157-mt7Q

Conversation

@aikido-autofix

Copy link
Copy Markdown

This pull request addresses identified vulnerabilities and implements the necessary fixes to strengthen our security posture. Please review and approve so we can merge these changes promptly and reduce potential risk.

Thanks , The security team.

This PR will resolve the following CVEs:

CVE ID Severity Description
CVE-2022-45688
HIGH
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
CVE-2023-5072
HIGH
Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
CVE-2025-11226
MEDIUM
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program e...
AIKIDO-2025-10694
MEDIUM
Affected versions of this package do not properly validate the logback.xml configuration file when both the Janino library and the Spring Framework are present on the classpath. An attacker can execute arbitrary code by compromising an existing configuration file or injecting a malicious environme...

Related Tasks:

@aikido-autofix aikido-autofix Bot requested a review from a team as a code owner November 11, 2025 14:21
@aikido-autofix aikido-autofix Bot added the aikido Label created by Aikido AutoFix label Nov 11, 2025
@sonarqubecloud

Copy link
Copy Markdown

@aikido-autofix aikido-autofix Bot closed this Nov 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aikido Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants