Описание
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
A flaw was found in the logback package. When using a specially-crafted configuration, this issue could allow a remote authenticated attacker to execute arbitrary code loaded from LDAP servers.
Отчет
Red Hat Satellite shipped affected versions, however, it is not vulnerable because the product doesn't meet the conditions needed to perform the attack.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | logback-classic | Out of support scope | ||
| Red Hat Integration Camel K 1 | logback-classic | Affected | ||
| Red Hat Integration Camel Quarkus 1 | logback-classic | Not affected | ||
| Red Hat JBoss BRMS 6 | logback-classic | Out of support scope | ||
| Red Hat JBoss Fuse 6 | logback-classic | Out of support scope | ||
| Red Hat Fuse 7.11 | logback-classic | Fixed | RHSA-2022:5532 | 07.07.2022 |
| Red Hat Satellite 6.11 for RHEL 7 | candlepin | Fixed | RHSA-2022:5498 | 05.07.2022 |
| Red Hat Satellite 6.11 for RHEL 8 | candlepin | Fixed | RHSA-2022:5498 | 05.07.2022 |
| RHDM 7.12.1 | logback-classic | Fixed | RHSA-2022:1110 | 29.03.2022 |
| RHPAM 7.12.1 | logback-classic | Fixed | RHSA-2022:1108 | 29.03.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.6 Medium
CVSS3
Связанные уязвимости
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
In logback version 1.2.7 and prior versions, an attacker with the requ ...
Security update for maven and recommended update for antlr3, minlog, sbt, xmvn
EPSS
6.6 Medium
CVSS3