Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

logback-access-1.6.5-2.1 RPM for noarch

From OpenSuSE Ports Tumbleweed for noarch

Name: logback-access Distribution: openSUSE Tumbleweed
Version: 1.6.5 Vendor: openSUSE
Release: 2.1 Build date: Sat Oct 3 09:45:32 2026
Group: Development/Libraries/Java Build host: reproducible
Size: 1887 Source RPM: logback-1.6.5-2.1.src.rpm
Packager: http://bugs.opensuse.org
Url: https://logback.qos.ch/
Summary: Logback-access module for Servlet integration
The logback-access module integrates with Servlet containers, such as Tomcat
and Jetty, to provide HTTP-access log functionality. Note that you could
easily build your own module on top of logback-core.

Provides

Requires

License

EPL-1.0 OR LGPL-2.1-or-later

Changelog

* Thu Oct 01 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to upstream version 1.6.5
    * Changes of version 1.6.5
      + Fixed a vulnerability (bsc#1284124, CVE-2026-104721) closely
      related to CVE-2026-19880 (bsc#1284020). The fix made in
      version 1.6.3, which strips forward and backward slashes from
      MDC values, was not sufficient. An MDC value could still
      contain relative path components such as .., variable
      references such as /, or characters that are special in file
      name patterns and email addresses.
      MDCBasedDiscriminator, used by SiftingAppender, now rejects
      MDC values instead of stripping characters from them. An MDC
      value is rejected if it is empty, if it is longer than 64
      characters, if it contains the sequence .., or if it contains
      any of the following characters: / \ $ { } [ ] ( ) | ? * + % ,
      @. When an MDC value is rejected, the discriminator returns
      the value of its DefaultValue property. A warning is emitted
      for each rejected value. These warnings are rate-limited.
      + When compression is enabled, TimeBasedRollingPolicy and
      SizeAndTimeBasedRollingPolicy now also remove old log files
      that were never compressed, for example because the
      application was not running at rollover time. Previously, such
      files were ignored by maxHistory and accumulated indefinitely.
      + SimpleInvocationGate, deprecated in version 1.6.3, is now
      marked for removal. Use FixedIntervalInvocationGate instead.
    * Changes of version 1.6.4
      + Variable substitution is again applied to the scan attribute
      of the <configuration> element. The scanning refactoring in
      version 1.5.27 had dropped substitution, so values such as
      ${logback.scan.enabled:-true} were no longer resolved. As
      before version 1.5.27, an unrecognized non-empty value turns
      scanning on. The same substitution now applies to the scan
      attribute of <propertiesConfigurator>.
      + OutputStreamAppender and FileAppender now handle stateful
      encoders. The Encoder interface has a new default method
      called isStateful(), which returns false. An encoder that
      keeps state between calls to encode() can return true. For
      such encoders, the appender holds its write lock while
      encoding and while writing, so the output of concurrent
      appends cannot interleave. Stateless encoders still encode
      outside the lock, so their performance does not change.
      Existing encoders need no changes.
      + Several race conditions in OutputStreamAppender and
      FileAppender were fixed. The appender is now marked started
      and the encoder header is written while the same lock is
      held, so a concurrent append can no longer write an event
      before the header. After acquiring the lock, the appender
      checks again whether it has been stopped, so no event is
      written after the footer. In prudent mode, FileAppender now
      encodes and writes each event while holding the lock.
      + Fixed a data race on the logger count in LoggerContext.
      Loggers are created under the lock of their parent logger, so
      loggers with different parents could be created at the same
      time and increments of the shared counter could be lost. As a
      result, LoggerContext.size() could return a value lower than
      the actual number of loggers. The counter is now an
      AtomicInteger.
      + TimeBasedRollingPolicy now supports half-day periods. Date
      patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a},
      used to be detected as daily and rolled over only at
      midnight. They now roll over at both 00:00 and 12:00. This
      issue was reported in issues/976 by shakthifuture.
      + If org.jline.jansi.AnsiConsole cannot be found on the class
      path, JansiConsoleAppender now emits warnings that explain
      how to add org.jline:jansi-core and then writes to the plain
      console stream. See codes.html#missingJlineJansi.
      + The unused
      ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was
      removed. LogbackMDCAdapter remains the default MDC adapter.
    * Changes of version 1.6.3
      + In relation to CVE-2026-19880 (bsc#1284020),
      MDCBasedDiscriminator (used by SiftingAppender) now strips
      forward and backward slashes (/, \) from MDC values before
      they are used as discriminating keys. This prevents path
      segments from escaping into destinations controlled by an
      attacker. When sanitisation actually changes a value, a
      warning is emitted; the warning is rate-limited (a small
      batch, then a lull of about ten minutes).
      + Colour console support is split out into a dedicated
      JansiConsoleAppender
      (ch.qos.logback.core.JansiConsoleAppender). It wraps stdout
      or stderr with Jansi so ANSI escape sequences (for example
      coloured patterns) render correctly on terminals that need
      it, notably Windows. Prefer this class over the older path
      described next.
      + The withJansi property on ConsoleAppender is deprecated.
      Existing configurations that still set
      <withJansi>true</withJansi> continue to work for
      compatibility, but new setups should use JansiConsoleAppender
      instead.
      + ConsoleAppender no longer treats the process console as an
      exclusive resource: stopping it does not close System.out /
      System.err. JansiConsoleAppender pairs each
      AnsiConsole.systemInstall() with systemUninstall() on stop,
      so repeated start/stop cycles do not leave Jansi installed or
      tear down streams shared with the rest of the JVM.
      + Invocation throttling helpers were reworked:
      SimpleInvocationGate is renamed FixedIntervalInvocationGate,
      and BatchedFixedIntervalInvocationGate allows a short burst
      of invocations before applying a fixed lull. The sanitisation
      warning above uses the batched gate.
      + The JPMS module-info for logback-core now exports the
      ch.qos.logback.core.property package, which had been missing
      from the module descriptor.
    * Changes of version 1.6.2
      + Configuration analysis now detects contradictory caller-data
      inclusion instructions. For example, an AsyncAppender,
      SocketAppender or SMTPAppender with includeCallerData left at
      the default false is incompatible with a layout or encoder
      pattern that uses a caller-data converter such as %C, %M, %L,
      %F, %l or %caller. At runtime those converters would print
      question marks and still incur extraction cost on a worker
      thread. Logback now emits a configuration-time warning when
      such instructions disagree. See
      codes.html#callerContradiction for details. This issue was
      reported in issues/1059 by leeychee. The initial analysis was
      contributed by seonwoo_jung.
      + Caller-contradiction analysis can be turned off by setting
      the logback.skipCallerContradictionAnalysis variable to true,
      either as a system property
      (-Dlogback.skipCallerContradictionAnalysis=true) or as a
      property in the configuration file:
      <property name="logback.skipCallerContradictionAnalysis"
      value="true"/>
      + SimpleSocketServer and SimpleSSLSocketServer now require an
      explicit client IP whitelist. On the command line, pass one
      or more allowed addresses (single IPs or CIDR ranges) after
      the configuration file. An empty whitelist means no clients
      are accepted. When embedding the server programmatically,
      register allowed addresses with
      addAllowedClientAddress(String) or
      setAllowedClientAddresses(Collection) before clients connect.
      See the documentation on restricting client access.
      + Added ThrowableProxyVOBuilder for assembling a
      ThrowableProxyVO field by field, with a corresponding
      ThrowableProxyVO.builder() entry point.
      + Dependency analysis handlers now run their postHandle method
      after child models have been processed, so checks that depend
      on nested appenders (such as caller-contradiction analysis)
      see a complete picture.
      + Updated several dependencies, including Angus Mail to 2.0.4
      and Jetty (test) to 12.1.12.
    * Changes of version 1.6.1
      + In TimeBasedRollingPolicy, when the file option is set, the
      intermediate file renamed before asynchronous compression now
      receives the target archive name without the compression
      suffix (e.g. `.gz`, `.zip`, `.xz`). Previously it used a
      nanotime-based `.tmp` suffix. This makes the file easier to
      identify if compression fails during rollover.
      + On GZ, ZIP, or XZ compression failure, the original
      (uncompressed) log file is no longer deleted. Compression
      strategies now delete the source file only after successful
      compression and emit a warning that the original was left
      intact.
      + ConsoleAppender with <withJansi> now probes JLine's
      org.jline.jansi.AnsiConsole first and falls back to the
      legacy FuseSource org.fusesource.jansi.AnsiConsole class.
      This keeps ANSI coloring working after Jansi moved under the
      JLine project. The optional org.jline:jansi-core artifact is
      declared as a dependency alongside the existing FuseSource
      jansi dependency. A preferredJansiClassName property was
      added for tests.
      + LayoutWrappingEncoder now reports an error at start() when no
      layout is set and guards encode() against a null layout.
      Previously, a missing layout (for example after an ignored
      <if>/<then>/<else> branch) allowed the encoder to start and
      then fail with a NullPointerException on every event,
      resulting in silent log loss.
      + FileCollisionAnalyser now detects file collisions involving
      nested appenders of SiftingAppender. When the nested file or
      fileNamePattern does not textually reference the
      discriminator key (e.g. ${userId}), a warning is issued at
      configuration time naming the appender, the key, and the
      shared target. This closes a gap where statically declared
      file appenders were checked but sifted nested appenders were
      not.
      + More defensive handling in SyslogOutputStream and
      SyslogAppenderBase: the close() method now ensures that
      resources are closed, writes and flushes check that the
      underlying resources are in a valid state and fallback to
      no-op otherwise.
  - Added patch:
    * jline-3.30.x.patch
      + modify the imported module to correspond to jline3 3.30.x
      module name of jansi-core artifact.
* Fri Jul 24 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to upstream version 1.6.0
    * Notable changes
      In version 1.5.37 and subsequently in 1.6.x, support for
      Janino-based conditional expressions was removed. Evaluating
      arbitrary Java expressions with the Janino library had led to
      numerous security vulnerabilities.
      If you are upgrading from a version earlier than 1.5.37 and
      your configuration files still use those older Janino-style
      conditionals, you must migrate them to the new format using
      the <condition> element (available since version version
      1.5.20).
      The <condition> element accepts implementations of the
      PropertyCondition interface to decide whether a branch of the
      configuration should apply. Logback-core ships with several
      implementations of said interface. For details, see the
      https://logback.qos.ch/manual/configuration.html#conditional
    * Changes
      + Removed deprecated variables
      ° ch.qos.logback.classic.PatternLayout#DEFAULT_CONVERTER_MAP
      ° ch.qos.logback.classic.PatternLayout#defaultConverterMap
      ° ch.qos.logback.classic.util.ContextInitializer
      [#]AUTOCONFIG_FILE
      ° ch.qos.logback.classic.util.ContextInitializer
      [#]TEST_AUTOCONFIG_FILE
      ° ch.qos.logback.classic.util.ContextInitializer
      [#]CONFIG_FILE_PROPERTY
      + Remove deprecated methods
      ° ch.qos.logback.classic.PatternLayout
      [#]getDefaultConverterMap()
      ° ch.qos.logback.core.util.ExecutorServiceUtil
      [#]newExecutorService()
      ° ch.qos.logback.core.util.VersionUtil
      [#]getVersionOfArtifact(Class<?>)
      ° ch.qos.logback.core.pattern.PatternLayoutBase
      [#]setContextForConverters
      ° ch.qos.logback.core.pattern.PatternLayoutEncoderBase
      [#]setOutputPatternAsPresentationHeader
      ° ch.qos.logback.core.joran.spi.ConfigurationWatchList
      [#]changeDetected
      ° ch.qos.logback.core.joran.GenericXMLConfigurator
      [#]informContextOfURLUsedForConfiguration
      ° ch.qos.logback.core.model.ModelUtil#setProperty
      ° ch.qos.logback.core.model.ModelUtil#setProperties
      ° ch.qos.logback.core.joran.action.PreconditionValidator
      [#]generic
      ° ch.qos.logback.core.util.EnvUtil#logbackVersion
      ° ch.qos.logback.classic.util.ClassicEnvUtil
      [#]getVersionOfLogbackClassic
      + Remove deprecated class
      ° ch.qos.logback.classic.turbo.ReconfigureOnChangeFilter
      + In AsyncAppenderBase, the put(ILoggingEvent) method now has
      the protected modifier to allow access from derived classes
      + Bump SLF4J dependency to version 2.0.18.
* Wed Jul 15 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to upstream version 1.5.38
    * Change of 1.5.38
      + In HardenedObjectInputStream, fixed a typo preventing
      Throwable objects from being white-filtered
    * Change of 1.5.37
      + Given the numerous vulnerabilities related to conditional
      configuration processing based on the evaluation of Java
      expressions using the Janino library, support for such
      expressions has been removed
  - Removed patch:
    * new-janino.patch
      + not needed
* Mon Jul 13 2026 Fridrich Strba <fstrba@suse.com>
  - Do not use the slf4j2 compatibility package, as the base slf4j
    package is now on version 2.0.18
* Fri Jun 26 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to upstream version 1.5.36
    * Changes of 1.5.36
      + The 'condition' attribute in <if> elements now reject certain
      references that are associated with ACE attacks
      (bsc#1269222, CVE-2026-13006).
    * Changes of 1.5.35
      + The 'condition' attribute in <if> elements now rejects unicode
      escape sequences (\u and \U). This closes a bypass of the
      existing prohibition on the new operator in Janino-evaluated
      conditions (bsc#1269222, CVE-2026-13006). Please note that the
      version 1.5.36 provides the full fix to this vulnerability.
      + Added ConfiguratorRank.AUTHENTICATING (rank 100), the highest
      configurator rank, for certified/authenticating configurators
      discovered via the ServiceLoader mechanism. ContextInitializer
      now requires that at most one such configurator exist on the
      classpath; if more than one is found, initialization aborts
      with an error.
      + ConsoleCharsetPropertyDefiner is no longer shipped. The Java
      21 multi-release compilation of logback-core has been
      disabled, which removes this class from the published
      artifact. Configurations that referenced
      ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner
      will need an alternative approach for console charset
      detection.
      + The logback-examples module is now included in the set of
      artifacts published to Maven Central.
      + JoranConfigurator.makeAnotherInstance() and
      DefaultJoranConfigurator.performMultiStepConfigurationFileSearch()
      are now protected, allowing derived configurators to override
      these methods.
* Wed Jun 10 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to upstream version 1.5.34
    * General changes between series
      + The 1.2.x series has been deprecated for several years and is
      no longer maintained
      + In Logback 1.2.x/1.3.x, few optional components depend on
      Java EE, whereas in logback versions 1.4.x/1.5.x, these
      optional components depend on Jakarta EE. The 1.5.x series
      continues the 1.4.x series, but with logback-access relocated
      to its own repository
    * Fixes
      + In case certain StackTraceElement values returned by the
      Throwable.getStackTrace method are null,
      StackTraceElementProxy substitutes a dummy instance instead of
      throwing an IllegalArgumentException (#1040)
      + HardenedObjectInputStream will now throw an
      InvalidClassException during deserialization attempts of Proxy
      classes (bsc#1266783, CVE-2026-10532)
      + PropertiesConfiguratorModelHandler now registers properties
      file URLs to the ConfigurationWatchList when scan is enabled
      (via local scan="true" attribute or top-level configuration
      scan), ensuring changes are detected and reconfiguration
      occurs (issues/1034)
      + When processing <conversionRule> elements and both class and
      converterClass attributes are specified, silently use the
      class attribute without issuing a warning. However, if the
      attribute values differ, a warning will be issued (issues/1031)
      + HardenedModelInputStream will no longer accept to deserialize
      all classes located under the "java.lang" and "java.util"
      packages but only a limited number of explicitly authorized
      classes in those packages (bsc#1266783, CVE-2026-9828)
      + SSL parameters for SSLSocketAppender now enable hostname
      verification by default. Moreover, the default protocol is now
      "TLSv1.2"
      + When printing the status message field,
      ViewStatusMessagesServletBase now escapes special characters
      such as "&" as character entities
  - Removed patches:
    * logback-1.2.3-getCallerClass.patch
    * logback-CVE-2024-12801-CVE-2024-12798.patch
    * logback-CVE-2025-11226.patch
    * logback-CVE-2026-1225.patch
      + not needed with this version
  - Added patch:
    * new-janino.patch
      + upgrade to new janino that has packages in org.codehaus
      namespace
* Thu Jan 29 2026 Fridrich Strba <fstrba@suse.com>
  - Added patch:
    * logback-CVE-2026-1225.patch
      + backport of upstream fix for bsc#1257094, CVE-2026-1225: ACE
      vulnerability in configuration file
* Fri Oct 03 2025 Fridrich Strba <fstrba@suse.com>
  - Upgrade to upstream version 1.2.13
    * Fixed NPE in ThrowableProxy if extractSupressedThrowables method
      returns null. This fixes LOGBACK-1623
    * Fixed incorrect use of HttpServletResponse.getStatus in
      logback-access as reported in LOGBACK-1580
    * Fixed incorrect use of HttpServletRequest.getParameterNames()
      logback-access as reported in LOGBACK-1581
    * Fixed incorrect SCP URL in Maven pom.xml. This issue was
      reported in LOGBACK-1633
    * Fixes for CVE-2023-6481 as well CVE-2023-6378 were back-ported
      into the 1.2.x branch. Fixes will be effective only when run
      under Java 9 and later.
      Note that a successful exploitation of
      CVE-2023-6378/CVE-2023-6381 requires that logback-receiver
      component is enabled and also reachable by the attacker.
  - Removed patch:
    * logback-1.2.8-jetty.patch
      + not needed with this version
  - Added patch:
    * logback-CVE-2025-11226.patch
      + backport of upstream fix for bsc#1250715, CVE-2025-11226: ACE
      vulnerability in conditional configuration file processing
* Fri Mar 28 2025 Fridrich Strba <fstrba@suse.com>
  - Added patch:
    * filtering.patch
      + Newer maven-filtering versions will throw error when trying
      to filter binary files and failing to do so. This avoids
      filtering on *.jks (Java Key Store) files.
* Wed Jan 08 2025 Gus Kenion <gus.kenion@suse.com>
  - CVE-2024-12798 (bsc#1234742) Arbitrary code execution via
    JaninoEventEvaluator
    * Resolution: remove JaninoEventEvaluator
  - CVE-2024-12801 (bsc#1234743) Server-Side Request Forgery (SSRF)
    in SaxEventRecorder
    * Resolution: prevent Server-Side Request Forgery (SSRF) attacks
      by ignoring external DTD files in DOCTYPE
    * Remove SaxEventRecorder
  - Add logback-CVE-2024-12801-CVE-2024-12798.patch
* Wed Feb 21 2024 Gus Kenion <gus.kenion@suse.com>
  - Use %patch -P N instead of deprecated %patchN.
* Sat Sep 09 2023 Fridrich Strba <fstrba@suse.com>
  - Reproducible builds: use SOURCE_DATE_EPOCH for timestamp

Files

/usr/share/licenses/logback-access
/usr/share/licenses/logback-access/LICENSE.txt
/usr/share/maven-metadata/logback-access.xml
/usr/share/maven-poms/logback
/usr/share/maven-poms/logback/logback-access.pom


Generated by rpm2html 1.8.1

Fabrice Bellet, Fri Oct 9 00:22:05 2026