| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: logback-access | Distribution: openSUSE Tumbleweed |
| Version: 1.6.5 | Vendor: openSUSE |
| Release: 2.1 | Build date: Sat Oct 3 09:45:32 2026 |
| Group: Development/Libraries/Java | Build host: reproducible |
| Size: 1887 | Source RPM: logback-1.6.5-2.1.src.rpm |
| Packager: http://bugs.opensuse.org | |
| Url: https://logback.qos.ch/ | |
| Summary: Logback-access module for Servlet integration | |
The logback-access module integrates with Servlet containers, such as Tomcat and Jetty, to provide HTTP-access log functionality. Note that you could easily build your own module on top of logback-core.
EPL-1.0 OR LGPL-2.1-or-later
* Thu Oct 01 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to upstream version 1.6.5
* Changes of version 1.6.5
+ Fixed a vulnerability (bsc#1284124, CVE-2026-104721) closely
related to CVE-2026-19880 (bsc#1284020). The fix made in
version 1.6.3, which strips forward and backward slashes from
MDC values, was not sufficient. An MDC value could still
contain relative path components such as .., variable
references such as /, or characters that are special in file
name patterns and email addresses.
MDCBasedDiscriminator, used by SiftingAppender, now rejects
MDC values instead of stripping characters from them. An MDC
value is rejected if it is empty, if it is longer than 64
characters, if it contains the sequence .., or if it contains
any of the following characters: / \ $ { } [ ] ( ) | ? * + % ,
@. When an MDC value is rejected, the discriminator returns
the value of its DefaultValue property. A warning is emitted
for each rejected value. These warnings are rate-limited.
+ When compression is enabled, TimeBasedRollingPolicy and
SizeAndTimeBasedRollingPolicy now also remove old log files
that were never compressed, for example because the
application was not running at rollover time. Previously, such
files were ignored by maxHistory and accumulated indefinitely.
+ SimpleInvocationGate, deprecated in version 1.6.3, is now
marked for removal. Use FixedIntervalInvocationGate instead.
* Changes of version 1.6.4
+ Variable substitution is again applied to the scan attribute
of the <configuration> element. The scanning refactoring in
version 1.5.27 had dropped substitution, so values such as
${logback.scan.enabled:-true} were no longer resolved. As
before version 1.5.27, an unrecognized non-empty value turns
scanning on. The same substitution now applies to the scan
attribute of <propertiesConfigurator>.
+ OutputStreamAppender and FileAppender now handle stateful
encoders. The Encoder interface has a new default method
called isStateful(), which returns false. An encoder that
keeps state between calls to encode() can return true. For
such encoders, the appender holds its write lock while
encoding and while writing, so the output of concurrent
appends cannot interleave. Stateless encoders still encode
outside the lock, so their performance does not change.
Existing encoders need no changes.
+ Several race conditions in OutputStreamAppender and
FileAppender were fixed. The appender is now marked started
and the encoder header is written while the same lock is
held, so a concurrent append can no longer write an event
before the header. After acquiring the lock, the appender
checks again whether it has been stopped, so no event is
written after the footer. In prudent mode, FileAppender now
encodes and writes each event while holding the lock.
+ Fixed a data race on the logger count in LoggerContext.
Loggers are created under the lock of their parent logger, so
loggers with different parents could be created at the same
time and increments of the shared counter could be lost. As a
result, LoggerContext.size() could return a value lower than
the actual number of loggers. The counter is now an
AtomicInteger.
+ TimeBasedRollingPolicy now supports half-day periods. Date
patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a},
used to be detected as daily and rolled over only at
midnight. They now roll over at both 00:00 and 12:00. This
issue was reported in issues/976 by shakthifuture.
+ If org.jline.jansi.AnsiConsole cannot be found on the class
path, JansiConsoleAppender now emits warnings that explain
how to add org.jline:jansi-core and then writes to the plain
console stream. See codes.html#missingJlineJansi.
+ The unused
ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was
removed. LogbackMDCAdapter remains the default MDC adapter.
* Changes of version 1.6.3
+ In relation to CVE-2026-19880 (bsc#1284020),
MDCBasedDiscriminator (used by SiftingAppender) now strips
forward and backward slashes (/, \) from MDC values before
they are used as discriminating keys. This prevents path
segments from escaping into destinations controlled by an
attacker. When sanitisation actually changes a value, a
warning is emitted; the warning is rate-limited (a small
batch, then a lull of about ten minutes).
+ Colour console support is split out into a dedicated
JansiConsoleAppender
(ch.qos.logback.core.JansiConsoleAppender). It wraps stdout
or stderr with Jansi so ANSI escape sequences (for example
coloured patterns) render correctly on terminals that need
it, notably Windows. Prefer this class over the older path
described next.
+ The withJansi property on ConsoleAppender is deprecated.
Existing configurations that still set
<withJansi>true</withJansi> continue to work for
compatibility, but new setups should use JansiConsoleAppender
instead.
+ ConsoleAppender no longer treats the process console as an
exclusive resource: stopping it does not close System.out /
System.err. JansiConsoleAppender pairs each
AnsiConsole.systemInstall() with systemUninstall() on stop,
so repeated start/stop cycles do not leave Jansi installed or
tear down streams shared with the rest of the JVM.
+ Invocation throttling helpers were reworked:
SimpleInvocationGate is renamed FixedIntervalInvocationGate,
and BatchedFixedIntervalInvocationGate allows a short burst
of invocations before applying a fixed lull. The sanitisation
warning above uses the batched gate.
+ The JPMS module-info for logback-core now exports the
ch.qos.logback.core.property package, which had been missing
from the module descriptor.
* Changes of version 1.6.2
+ Configuration analysis now detects contradictory caller-data
inclusion instructions. For example, an AsyncAppender,
SocketAppender or SMTPAppender with includeCallerData left at
the default false is incompatible with a layout or encoder
pattern that uses a caller-data converter such as %C, %M, %L,
%F, %l or %caller. At runtime those converters would print
question marks and still incur extraction cost on a worker
thread. Logback now emits a configuration-time warning when
such instructions disagree. See
codes.html#callerContradiction for details. This issue was
reported in issues/1059 by leeychee. The initial analysis was
contributed by seonwoo_jung.
+ Caller-contradiction analysis can be turned off by setting
the logback.skipCallerContradictionAnalysis variable to true,
either as a system property
(-Dlogback.skipCallerContradictionAnalysis=true) or as a
property in the configuration file:
<property name="logback.skipCallerContradictionAnalysis"
value="true"/>
+ SimpleSocketServer and SimpleSSLSocketServer now require an
explicit client IP whitelist. On the command line, pass one
or more allowed addresses (single IPs or CIDR ranges) after
the configuration file. An empty whitelist means no clients
are accepted. When embedding the server programmatically,
register allowed addresses with
addAllowedClientAddress(String) or
setAllowedClientAddresses(Collection) before clients connect.
See the documentation on restricting client access.
+ Added ThrowableProxyVOBuilder for assembling a
ThrowableProxyVO field by field, with a corresponding
ThrowableProxyVO.builder() entry point.
+ Dependency analysis handlers now run their postHandle method
after child models have been processed, so checks that depend
on nested appenders (such as caller-contradiction analysis)
see a complete picture.
+ Updated several dependencies, including Angus Mail to 2.0.4
and Jetty (test) to 12.1.12.
* Changes of version 1.6.1
+ In TimeBasedRollingPolicy, when the file option is set, the
intermediate file renamed before asynchronous compression now
receives the target archive name without the compression
suffix (e.g. `.gz`, `.zip`, `.xz`). Previously it used a
nanotime-based `.tmp` suffix. This makes the file easier to
identify if compression fails during rollover.
+ On GZ, ZIP, or XZ compression failure, the original
(uncompressed) log file is no longer deleted. Compression
strategies now delete the source file only after successful
compression and emit a warning that the original was left
intact.
+ ConsoleAppender with <withJansi> now probes JLine's
org.jline.jansi.AnsiConsole first and falls back to the
legacy FuseSource org.fusesource.jansi.AnsiConsole class.
This keeps ANSI coloring working after Jansi moved under the
JLine project. The optional org.jline:jansi-core artifact is
declared as a dependency alongside the existing FuseSource
jansi dependency. A preferredJansiClassName property was
added for tests.
+ LayoutWrappingEncoder now reports an error at start() when no
layout is set and guards encode() against a null layout.
Previously, a missing layout (for example after an ignored
<if>/<then>/<else> branch) allowed the encoder to start and
then fail with a NullPointerException on every event,
resulting in silent log loss.
+ FileCollisionAnalyser now detects file collisions involving
nested appenders of SiftingAppender. When the nested file or
fileNamePattern does not textually reference the
discriminator key (e.g. ${userId}), a warning is issued at
configuration time naming the appender, the key, and the
shared target. This closes a gap where statically declared
file appenders were checked but sifted nested appenders were
not.
+ More defensive handling in SyslogOutputStream and
SyslogAppenderBase: the close() method now ensures that
resources are closed, writes and flushes check that the
underlying resources are in a valid state and fallback to
no-op otherwise.
- Added patch:
* jline-3.30.x.patch
+ modify the imported module to correspond to jline3 3.30.x
module name of jansi-core artifact.
* Fri Jul 24 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to upstream version 1.6.0
* Notable changes
In version 1.5.37 and subsequently in 1.6.x, support for
Janino-based conditional expressions was removed. Evaluating
arbitrary Java expressions with the Janino library had led to
numerous security vulnerabilities.
If you are upgrading from a version earlier than 1.5.37 and
your configuration files still use those older Janino-style
conditionals, you must migrate them to the new format using
the <condition> element (available since version version
1.5.20).
The <condition> element accepts implementations of the
PropertyCondition interface to decide whether a branch of the
configuration should apply. Logback-core ships with several
implementations of said interface. For details, see the
https://logback.qos.ch/manual/configuration.html#conditional
* Changes
+ Removed deprecated variables
° ch.qos.logback.classic.PatternLayout#DEFAULT_CONVERTER_MAP
° ch.qos.logback.classic.PatternLayout#defaultConverterMap
° ch.qos.logback.classic.util.ContextInitializer
[#]AUTOCONFIG_FILE
° ch.qos.logback.classic.util.ContextInitializer
[#]TEST_AUTOCONFIG_FILE
° ch.qos.logback.classic.util.ContextInitializer
[#]CONFIG_FILE_PROPERTY
+ Remove deprecated methods
° ch.qos.logback.classic.PatternLayout
[#]getDefaultConverterMap()
° ch.qos.logback.core.util.ExecutorServiceUtil
[#]newExecutorService()
° ch.qos.logback.core.util.VersionUtil
[#]getVersionOfArtifact(Class<?>)
° ch.qos.logback.core.pattern.PatternLayoutBase
[#]setContextForConverters
° ch.qos.logback.core.pattern.PatternLayoutEncoderBase
[#]setOutputPatternAsPresentationHeader
° ch.qos.logback.core.joran.spi.ConfigurationWatchList
[#]changeDetected
° ch.qos.logback.core.joran.GenericXMLConfigurator
[#]informContextOfURLUsedForConfiguration
° ch.qos.logback.core.model.ModelUtil#setProperty
° ch.qos.logback.core.model.ModelUtil#setProperties
° ch.qos.logback.core.joran.action.PreconditionValidator
[#]generic
° ch.qos.logback.core.util.EnvUtil#logbackVersion
° ch.qos.logback.classic.util.ClassicEnvUtil
[#]getVersionOfLogbackClassic
+ Remove deprecated class
° ch.qos.logback.classic.turbo.ReconfigureOnChangeFilter
+ In AsyncAppenderBase, the put(ILoggingEvent) method now has
the protected modifier to allow access from derived classes
+ Bump SLF4J dependency to version 2.0.18.
* Wed Jul 15 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to upstream version 1.5.38
* Change of 1.5.38
+ In HardenedObjectInputStream, fixed a typo preventing
Throwable objects from being white-filtered
* Change of 1.5.37
+ Given the numerous vulnerabilities related to conditional
configuration processing based on the evaluation of Java
expressions using the Janino library, support for such
expressions has been removed
- Removed patch:
* new-janino.patch
+ not needed
* Mon Jul 13 2026 Fridrich Strba <fstrba@suse.com>
- Do not use the slf4j2 compatibility package, as the base slf4j
package is now on version 2.0.18
* Fri Jun 26 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to upstream version 1.5.36
* Changes of 1.5.36
+ The 'condition' attribute in <if> elements now reject certain
references that are associated with ACE attacks
(bsc#1269222, CVE-2026-13006).
* Changes of 1.5.35
+ The 'condition' attribute in <if> elements now rejects unicode
escape sequences (\u and \U). This closes a bypass of the
existing prohibition on the new operator in Janino-evaluated
conditions (bsc#1269222, CVE-2026-13006). Please note that the
version 1.5.36 provides the full fix to this vulnerability.
+ Added ConfiguratorRank.AUTHENTICATING (rank 100), the highest
configurator rank, for certified/authenticating configurators
discovered via the ServiceLoader mechanism. ContextInitializer
now requires that at most one such configurator exist on the
classpath; if more than one is found, initialization aborts
with an error.
+ ConsoleCharsetPropertyDefiner is no longer shipped. The Java
21 multi-release compilation of logback-core has been
disabled, which removes this class from the published
artifact. Configurations that referenced
ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner
will need an alternative approach for console charset
detection.
+ The logback-examples module is now included in the set of
artifacts published to Maven Central.
+ JoranConfigurator.makeAnotherInstance() and
DefaultJoranConfigurator.performMultiStepConfigurationFileSearch()
are now protected, allowing derived configurators to override
these methods.
* Wed Jun 10 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to upstream version 1.5.34
* General changes between series
+ The 1.2.x series has been deprecated for several years and is
no longer maintained
+ In Logback 1.2.x/1.3.x, few optional components depend on
Java EE, whereas in logback versions 1.4.x/1.5.x, these
optional components depend on Jakarta EE. The 1.5.x series
continues the 1.4.x series, but with logback-access relocated
to its own repository
* Fixes
+ In case certain StackTraceElement values returned by the
Throwable.getStackTrace method are null,
StackTraceElementProxy substitutes a dummy instance instead of
throwing an IllegalArgumentException (#1040)
+ HardenedObjectInputStream will now throw an
InvalidClassException during deserialization attempts of Proxy
classes (bsc#1266783, CVE-2026-10532)
+ PropertiesConfiguratorModelHandler now registers properties
file URLs to the ConfigurationWatchList when scan is enabled
(via local scan="true" attribute or top-level configuration
scan), ensuring changes are detected and reconfiguration
occurs (issues/1034)
+ When processing <conversionRule> elements and both class and
converterClass attributes are specified, silently use the
class attribute without issuing a warning. However, if the
attribute values differ, a warning will be issued (issues/1031)
+ HardenedModelInputStream will no longer accept to deserialize
all classes located under the "java.lang" and "java.util"
packages but only a limited number of explicitly authorized
classes in those packages (bsc#1266783, CVE-2026-9828)
+ SSL parameters for SSLSocketAppender now enable hostname
verification by default. Moreover, the default protocol is now
"TLSv1.2"
+ When printing the status message field,
ViewStatusMessagesServletBase now escapes special characters
such as "&" as character entities
- Removed patches:
* logback-1.2.3-getCallerClass.patch
* logback-CVE-2024-12801-CVE-2024-12798.patch
* logback-CVE-2025-11226.patch
* logback-CVE-2026-1225.patch
+ not needed with this version
- Added patch:
* new-janino.patch
+ upgrade to new janino that has packages in org.codehaus
namespace
* Thu Jan 29 2026 Fridrich Strba <fstrba@suse.com>
- Added patch:
* logback-CVE-2026-1225.patch
+ backport of upstream fix for bsc#1257094, CVE-2026-1225: ACE
vulnerability in configuration file
* Fri Oct 03 2025 Fridrich Strba <fstrba@suse.com>
- Upgrade to upstream version 1.2.13
* Fixed NPE in ThrowableProxy if extractSupressedThrowables method
returns null. This fixes LOGBACK-1623
* Fixed incorrect use of HttpServletResponse.getStatus in
logback-access as reported in LOGBACK-1580
* Fixed incorrect use of HttpServletRequest.getParameterNames()
logback-access as reported in LOGBACK-1581
* Fixed incorrect SCP URL in Maven pom.xml. This issue was
reported in LOGBACK-1633
* Fixes for CVE-2023-6481 as well CVE-2023-6378 were back-ported
into the 1.2.x branch. Fixes will be effective only when run
under Java 9 and later.
Note that a successful exploitation of
CVE-2023-6378/CVE-2023-6381 requires that logback-receiver
component is enabled and also reachable by the attacker.
- Removed patch:
* logback-1.2.8-jetty.patch
+ not needed with this version
- Added patch:
* logback-CVE-2025-11226.patch
+ backport of upstream fix for bsc#1250715, CVE-2025-11226: ACE
vulnerability in conditional configuration file processing
* Fri Mar 28 2025 Fridrich Strba <fstrba@suse.com>
- Added patch:
* filtering.patch
+ Newer maven-filtering versions will throw error when trying
to filter binary files and failing to do so. This avoids
filtering on *.jks (Java Key Store) files.
* Wed Jan 08 2025 Gus Kenion <gus.kenion@suse.com>
- CVE-2024-12798 (bsc#1234742) Arbitrary code execution via
JaninoEventEvaluator
* Resolution: remove JaninoEventEvaluator
- CVE-2024-12801 (bsc#1234743) Server-Side Request Forgery (SSRF)
in SaxEventRecorder
* Resolution: prevent Server-Side Request Forgery (SSRF) attacks
by ignoring external DTD files in DOCTYPE
* Remove SaxEventRecorder
- Add logback-CVE-2024-12801-CVE-2024-12798.patch
* Wed Feb 21 2024 Gus Kenion <gus.kenion@suse.com>
- Use %patch -P N instead of deprecated %patchN.
* Sat Sep 09 2023 Fridrich Strba <fstrba@suse.com>
- Reproducible builds: use SOURCE_DATE_EPOCH for timestamp
/usr/share/licenses/logback-access /usr/share/licenses/logback-access/LICENSE.txt /usr/share/maven-metadata/logback-access.xml /usr/share/maven-poms/logback /usr/share/maven-poms/logback/logback-access.pom
Generated by rpm2html 1.8.1
Fabrice Bellet, Fri Oct 9 00:22:05 2026