In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: NCSC.ch
Published: 2021-12-16T00:00:00
Updated: 2024-08-04T03:38:49.194Z
Reserved: 2021-10-15T00:00:00
Link: CVE-2021-42550
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-12-16T19:15:08.297
Modified: 2024-11-21T06:27:47.313
Link: CVE-2021-42550
Redhat