VDB

DEBIAN-CVE-2024-12801

DEBIAN-CVE-2024-12801 PUBLISHED CVSS 2.4000000953674316 LOW

Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in  XML configuration files.

Risk Scores

CVSS 4.0
2.4000000953674316
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:X/U:Clear

Affected Products

VendorProductVersions
Debian:11logback0, 1:1.2.8-1, 1:1.2.9-1
Debian:13logback1:1.2.11-6, 0, 1.2.11-6
Debian:14logback0, 0, 1.2.11-6
Debian:12logback1:1.2.11-6, *, 1:1.2.11-4

Timeline

  • Dec 19, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›