Update QOS.ch Logback to 1.2.0 or later in order to address threat CVE-2017-5929 with CVSS v3 Base Score 9.8.
From Logback News:
Release 1.2.0 fixes a rather severe serialization vulnerability in SocketServer and ServerSocketReceiver. Users running these components should upgrade immediately.