CVE-2021-42550
published 2021-12-16CVE-2021-42550: In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration…
PriorityP341medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
4.44%
90.4th percentile
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | logback | < logback 1:1.2.8-1 (bookworm) | logback 1:1.2.8-1 (bookworm) |
| qos.ch | logback | >= unspecified < 1.2.9 | 1.2.9 |
| qos.ch | logback | >= unspecified < 1.3.0-alpha11 | 1.3.0-alpha11 |
| qos | logback | <= 1.2.7 | — |
| qos | logback | — | — |
| qos | logback | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| qos | logback | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| qos | logback | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| qos | logback | >= 0 < 1:1.1.3-2ubuntu0.1~esm1 | 1:1.1.3-2ubuntu0.1~esm1 |
| qos | logback | >= 0 < 1:1.2.3-2ubuntu1~18.04.1+esm1 | 1:1.2.3-2ubuntu1~18.04.1+esm1 |
| qos | logback | >= 0 < 1:1.2.3-5ubuntu0.1~esm1 | 1:1.2.3-5ubuntu0.1~esm1 |
| qos | logback | >= 0 < 1:1.2.10-1ubuntu0.1~esm1 | 1:1.2.10-1ubuntu0.1~esm1 |
| redhat | satellite | — | — |
| siemens | sinec_nms | < 1.0.3 | 1.0.3 |
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
vendor_ubuntu6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
logback vulnerabilities
vendor_ubuntu·2025-07-02·CVSS 6.6
CVE-2023-6378 [MEDIUM] logback vulnerabilities
Title: logback vulnerabilities
Summary: Several security issues were fixed in logback.
It was discovered that logback could read malicious configuration files
from LDAP servers. An attacker with the required permissions could possibly
use this issue to execute arbitrary code. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-42550) It was
discovered that logback contained a serialization vulnerability. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-6378)
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEC Network Management System Logback Component
cisa_ics·2022-11-10·CVSS 6.6
[MEDIUM] Siemens SINEC Network Management System Logback Component
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC Network Management System Logback Component
Last RevisedNovember 10, 2022
Alert CodeICSA-22-314-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.6
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerability: Deserialization of Untrusted Data
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow attackers with write access to the logback configuration file to execute arbitrary code on the system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens SINEC NMS, a network management s
Red Hat
logback: remote code execution through JNDI call from within its configuration file
vendor_redhat·2021-12-16·CVSS 6.6
CVE-2021-42550 [MEDIUM] CWE-502 logback: remote code execution through JNDI call from within its configuration file
logback: remote code execution through JNDI call from within its configuration file
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
A flaw was found in the logback package. When using a specially-crafted configuration, this issue could allow a remote authenticated attacker to execute arbitrary code loaded from LDAP servers.
Statement: Red Hat Satellite shipped affected versions, however, it is not vulnerable because the product doesn't meet the conditions needed to perform the attack.
Package: logback-classic (Red Hat BPM Suite 6) - Out of support scope
Package: logback-classic (Red Hat Integration Camel K 1) - Affected
Debian
CVE-2021-42550: logback - In logback version 1.2.7 and prior versions, an attacker with the required privi...
vendor_debian·2021·CVSS 6.6
CVE-2021-42550 [MEDIUM] CVE-2021-42550: logback - In logback version 1.2.7 and prior versions, an attacker with the required privi...
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
Scope: local
bookworm: resolved (fixed in 1:1.2.8-1)
bullseye: open
forky: resolved (fixed in 1:1.2.8-1)
sid: resolved (fixed in 1:1.2.8-1)
trixie: resolved (fixed in 1:1.2.8-1)
OSV
logback vulnerabilities
osv·2025-07-02·CVSS 6.6
CVE-2021-42550 [MEDIUM] logback vulnerabilities
logback vulnerabilities
It was discovered that logback could read malicious configuration files
from LDAP servers. An attacker with the required permissions could possibly
use this issue to execute arbitrary code. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-42550) It was
discovered that logback contained a serialization vulnerability. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-6378)
GHSA
Deserialization of Untrusted Data in logback
ghsa·2021-12-17
CVE-2021-42550 [MEDIUM] CWE-502 Deserialization of Untrusted Data in logback
Deserialization of Untrusted Data in logback
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
OSV
Deserialization of Untrusted Data in logback
osv·2021-12-17
CVE-2021-42550 [MEDIUM] Deserialization of Untrusted Data in logback
Deserialization of Untrusted Data in logback
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
OSV
CVE-2021-42550: In logback version 1
osv·2021-12-16·CVSS 6.6
CVE-2021-42550 [MEDIUM] CVE-2021-42550: In logback version 1
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-42550 logback: remote code execution through JNDI call from within its configuration file
bugzilla·2021-12-17·CVSS 6.6
CVE-2021-42550 [MEDIUM] CVE-2021-42550 logback: remote code execution through JNDI call from within its configuration file
CVE-2021-42550 logback: remote code execution through JNDI call from within its configuration file
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
https://cve.report/CVE-2021-42550
https://jira.qos.ch/browse/LOGBACK-1591
Discussion:
References:
https://jira.qos.ch/browse/LOGBACK-1591
---
Red Hat Satellite does not give write access to the logback.xml nor use scan attribute in `` element of the configuration file; thus product is not vulnerable and mentioned exploit is not possible to perform.
---
This issue has been addressed in the following products:
RHPAM 7.12.1
Via RHSA-2022:1108 https://access.redhat.com/errata
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
CVE-2021-45046 (critical)
CVE-2021-4104 (high)
CVE-2021-42550 (moderate)
CVE-2021-45105 (moderate)
CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software can b
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
- CVE-2021-45046 (critical)
- CVE-2021-4104 (high)
- CVE-2021-42550 (moderate)
- CVE-2021-45105 (moderate)
- CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software
Crowdstrike
Java Logging Guide: The Basics
blogs_crowdstrike
Java Logging Guide: The Basics
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
Logging helps you understand how an application performs or what went wrong when something fails. This information can be critical for debugging and auditing purposes. Logs maintain a trail of every event during a program’s execution, making those records available for later analysis.
However, effective logging does not happen automatically. Application developers need to ensure an application is systematically logging important details in an easy-to-process format.
The most rudimentary approach to log
http://logback.qos.ch/news.htmlhttp://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlhttp://seclists.org/fulldisclosure/2022/Jul/11https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdfhttps://github.com/cn-panda/logbackRceDemohttps://jira.qos.ch/browse/LOGBACK-1591https://security.netapp.com/advisory/ntap-20211229-0001/http://logback.qos.ch/news.htmlhttp://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlhttp://seclists.org/fulldisclosure/2022/Jul/11https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdfhttps://github.com/cn-panda/logbackRceDemohttps://jira.qos.ch/browse/LOGBACK-1591https://security.netapp.com/advisory/ntap-20211229-0001/
2021-12-16
Published