Description
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
No analysis available yet.
Remediation
Vendor Solution
upgrade to >=1.2.9 or >=1.3.0-alpha11
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2454 | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
Github GHSA |
GHSA-668q-qrv7-99fm | Deserialization of Untrusted Data in logback |
Ubuntu USN |
USN-7616-1 | logback vulnerabilities |
References
History
Tue, 24 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | RCE from attacker with configuration edit priviledges through JNDI lookup | RCE from attacker with configuration edit priviledges through JNDI lookup |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Netapp
Subscribe
Cloud Manager
Subscribe
Service Level Manager
Subscribe
Snap Creator Framework
Subscribe
Qos
Subscribe
Logback
Subscribe
Redhat
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Fuse
Subscribe
Satellite
Subscribe
Siemens
Subscribe
Sinec Nms
Subscribe
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2024-08-04T03:38:49.194Z
Reserved: 2021-10-15T00:00:00.000Z
Link: CVE-2021-42550
No data.
Status : Modified
Published: 2021-12-16T19:15:08.297
Modified: 2024-11-21T06:27:47.313
Link: CVE-2021-42550
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN