PT-2024-10039 · Unknown+2 · Logback-Core+2

7Asecurity

·

Published

2024-12-19

·

Updated

2026-05-18

·

CVE-2024-12798

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/RE:L/U:Clear
Name of the Vulnerable Software and Affected Versions logback-core versions 0.1 through 1.3.14 logback-core versions 1.4.0 through 1.5.12
Description The issue is related to the JaninoEventEvaluator extension in logback-core, which allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege. Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension.
Recommendations For logback-core versions 0.1 through 1.3.14, consider disabling the JaninoEventEvaluator extension until a patch is available. For logback-core versions 1.4.0 through 1.5.12, consider disabling the JaninoEventEvaluator extension until a patch is available. As a temporary workaround, restrict access to configuration files to minimize the risk of exploitation. Avoid injecting environment variables that could point to malicious configuration files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00177
CLEANSTART-2026-CI66802
CLEANSTART-2026-DD05788
CLEANSTART-2026-GH89210
CLEANSTART-2026-KM27583
CLEANSTART-2026-SP91806
CLEANSTART-2026-VH41554
CVE-2024-12798
GHSA-PR98-23F8-JWXV
OESA-2025-1082
OPENSUSE-SU-2025:14627-1
OPENSUSE-SU-2025_0072-1
SUSE-SU-2025:0072-1

Affected Products

Debian
Suse
Logback-Core