Skip to content

CX: CVE-2021-42550 in Maven-ch.qos.logback:logback-core and 1.2.7 @ hello-world-java.master #5

@DhavalPatelPersistent

Description

@DhavalPatelPersistent

Description

In logback versions prior to 1.2.9 and 1.3.x prior to 1.3.0-alpha11, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

MEDIUM Vulnerable Package issue exists @ ch.qos.logback:logback-core in branch master

Vulnerability ID: CVE-2021-42550

Package Name: ch.qos.logback:logback-core

Severity: MEDIUM

CVSS Score: 6.6

Publish Date: 2021-12-16T19:15:00

Current Package Version: 1.2.7

Remediation Upgrade Recommendation: 1.2.9

Link To SCA

Reference – NVD link

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions