[PF-2978] High severity security issue - Upgrade logback-core #127
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
https://broadworkbench.atlassian.net/browse/PF-2978
CVE-2023-6378 is fixed as of logback
1.4.14
: https://logback.qos.ch/news.html#1.3.14However spring-boot pulls in logback versions which are vulnerable:
spring-boot:3.1.2
pulls inlogback-core:1.4.8
spring-boot:3.2.0
pulls inlogback-core:1.4.11
See also this spring-boot issue from today: spring-projects/spring-boot#38643
So I'm leaving spring-boot alone, and explicitly pulling in logback from TCL, which seems to work.
Downstream services will need to update their TCL dependency.