CVE-2024-12801
CVSS V2 None
CVSS V3 None
Description
Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to
forge requests by compromising logback configuration files in XML.
The attacks involves the modification of DOCTYPE declaration in XML configuration files.
Overview
- CVE ID
- CVE-2024-12801
- Assigner
- NCSC.ch
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-19T16:11:50.044Z
- Last Modified Date
- 2024-12-19T16:11:50.044Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://logback.qos.ch/news.html#1.5.13 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-12801 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-12801 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-20 13:21:12 | Added to TrackCVE |