• CVE-2024-12798

发布时间: 2025年1月24日

修改时间: 2025年1月24日

概要

ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension. A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 7.2
Attack Complexity Low
Privileges Required High
Scope Unchanged
Integrity High
User Interaction None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-1623 logback security update 2025年3月18日

影响产品

产品 状态
KY3.4-5 logback Fixed
KY3.5.3 logback Fixed
V6 logback Fixed
KY3.5.2 logback Fixed