VOOZH about

URL: https://jira.qos.ch/browse/LOGBACK-1591

⇱ Loading...


We are migrating this Jira service to Github. Issue creation is no longer possible on this server and must be done on Github. However, you may browse issues without an account. Editing or commenting on existing issues requires an account.

Please support SLF4J/logback/reload4j projects via Github donations and sponsorship.

Details

Description

Jira tickets are reserved for reporting bugs and not a support forum. Comments out of place will be deleted.

CVE-2021-42550 has been assigned.

The vulnerability is considered to pose a lesser threat than log4shell because it requires access to logback's configuration file by the attacker, sign of an already compromised system.
This CVE-2021-42550 is intended to prevent an escalation of an existing flaw to a higher threat level.

Logback should not be a vector in making an RCE possible even as a stepping stone for the attacker exploiting a prior existing vulnerability (in a different part of the system).

Attachments

Activity

People

👁 ceki
Ceki Gülcü
👁 ceki
Ceki Gülcü
Votes:
Vote for this issue
Watchers:
Start watching this issue

Dates

Created:
Updated:
Resolved: