PT-2024-17746 · Logback+2 · Logback+2

·

CVE-2024-12801

·

Published

2024-12-19

·

Updated

2026-07-10

CVSS v3.1

3.3

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions logback versions 0.1 through 1.3.14 logback versions 1.4.0 through 1.5.12
Description The issue allows an attacker to forge requests by compromising logback configuration files in XML. This is achieved by modifying the DOCTYPE declaration in XML configuration files, enabling Server-Side Request Forgery (SSRF) attacks.
Recommendations For logback versions 0.1 through 1.3.14, update to a version outside of this range to mitigate the risk. For logback versions 1.4.0 through 1.5.12, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting modifications to logback configuration files to prevent exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-CI66802
CLEANSTART-2026-DD05788
CLEANSTART-2026-GH89210
CLEANSTART-2026-KM27583
CLEANSTART-2026-SP91806
CLEANSTART-2026-VH41554
CLEANSTART-2026-XR78310
CVE-2024-12801
GHSA-6V67-2WR5-GVF4
OESA-2025-1082
OPENSUSE-SU-2025:14627-1
OPENSUSE-SU-2025_0072-1
SUSE-SU-2025:0072-1

Affected Products

Debian
Suse
Logback