CVE-2024-12801

Updated on 19 Dec 2024

Severity

Awaiting Analysis

Details

CVSS score
8.6

Overview

About vulnerability

Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.

The attacks involves the modification of DOCTYPE declaration in  XML configuration files.

Details

Affected product:
Eclipse Jetty , Logback , Spring , cxf , logging-log4j2 , netty , tika
Affected packages:
jetty-ajp @ 7.6.0.v20120127 (+1593 more)

Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.

The attacks involves the modification of DOCTYPE declaration in  XML configuration files.

Fixes