CVE-2021-42550
Summary
| CVE | CVE-2021-42550 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-16 19:15:00 UTC |
| Updated | 2022-12-12 21:13:00 UTC |
| Description | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| [LOGBACK-1591] Possibility of vulnerability - QOS.ch JIRA |
MISC |
jira.qos.ch |
|
| Full Disclosure: Open-Xchange Security Advisory 2022-07-21 |
FULLDISC |
seclists.org |
|
| CVE-2021-42550 Logback Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| GitHub - cn-panda/logbackRceDemo: The project is a simple vulnerability Demo environment written by SpringBoot. Here, I deliberately wrote a vulnerability environment where there are arbitrary file uploads, and then use the `scan` attribute in the loghack configuration file to cooperate with the logback vulnerability to implement RCE. |
MISC |
github.com |
|
| Open-Xchange App Suite 7.10.x Cross Site Scripting / Command Injection ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Logback News |
CONFIRM |
logback.qos.ch |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182610 Debian Security Update for logback (CVE-2021-42550)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 591301 Siemens SINEC NMS Arbitrary Code Execution Vulnerability (SSA-371761 V1.0.3)
- 753967 SUSE Enterprise Linux Security Update for maven and recommended update for antlr3, minlog, sbt, xmvn (SUSE-SU-2023:2097-1)
- 753968 SUSE Enterprise Linux Security Update for maven and recommended update for antlr3, minlog, sbt, xmvn (SUSE-SU-2023:2097-1)
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)