peter bassill · operator
$ cve CVE-2018-8088 JSON

CVE-2018-8088

9.8
CRITICAL · CVSS 3.1 · EPSS 14.7% (pctl 97)

Patch early

EPSS 14.7% — above the 10% action threshold.

Description

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.7% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploitnone known
Published2018-03-20
Last modified2026-06-17

Affected (14)

VendorProduct
oraclegoldengate application adapters
oraclegoldengate stream analytics
oracleutilities framework
qosslf4j
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatjboss enterprise application platform
redhatvirtualization
redhatvirtualization host

References

→ the Explorer  ·  watch your stack  ·  NVD