cbcvebase.
CVE-2021-42550
published 2021-12-16

CVE-2021-42550: In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration…

medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlogback< logback 1:1.2.8-1 (bookworm)logback 1:1.2.8-1 (bookworm)
qos.chlogback>= unspecified < 1.2.91.2.9
qos.chlogback>= unspecified < 1.3.0-alpha111.3.0-alpha11
qoslogback<= 1.2.7
qoslogback
qoslogback>= 0 < 1:1.2.8-11:1.2.8-1
qoslogback>= 0 < 1:1.2.8-11:1.2.8-1
qoslogback>= 0 < 1:1.2.8-11:1.2.8-1
qoslogback>= 0 < 1:1.1.3-2ubuntu0.1~esm11:1.1.3-2ubuntu0.1~esm1
qoslogback>= 0 < 1:1.2.3-2ubuntu1~18.04.1+esm11:1.2.3-2ubuntu1~18.04.1+esm1
qoslogback>= 0 < 1:1.2.3-5ubuntu0.1~esm11:1.2.3-5ubuntu0.1~esm1
qoslogback>= 0 < 1:1.2.10-1ubuntu0.1~esm11:1.2.10-1ubuntu0.1~esm1
redhatsatellite
siemenssinec_nms< 1.0.31.0.3

CVSS provenance

nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.6MEDIUM