CVE-2024-12801

CVSS V2 None CVSS V3 None
Description
Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in  XML configuration files.
Overview
  • CVE ID
  • CVE-2024-12801
  • Assigner
  • NCSC.ch
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-19T16:11:50.044Z
  • Last Modified Date
  • 2024-12-19T16:11:50.044Z
References
Reference URL Reference Tags
https://logback.qos.ch/news.html#1.5.13
History
Created Old Value New Value Data Type Notes
2024-12-20 13:21:12 Added to TrackCVE