Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
omar-napoleon committed Dec 20, 2024
1 parent 5d70588 commit 2502128
Showing 1 changed file with 2 additions and 5 deletions.
Original file line number Diff line number Diff line change
@@ -1,18 +1,15 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v67-2wr5-gvf4",
"modified": "2024-12-20T15:12:53Z",
"modified": "2024-12-20T15:12:55Z",
"published": "2024-12-19T18:31:37Z",
"aliases": [
"CVE-2024-12801"
],
"summary": "QOS.CH logback-core Server-Side Request Forgery vulnerability",
"details": "Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.\n \nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear"
}

],
"affected": [
{
Expand Down

0 comments on commit 2502128

Please sign in to comment.