Deserialization of Untrusted Data in logback
Moderate severity
GitHub Reviewed
Published
Dec 17, 2021
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Dec 16, 2021
Reviewed
Dec 17, 2021
Published to the GitHub Advisory Database
Dec 17, 2021
Last updated
Jan 30, 2023
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
References