Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19880

Опубликовано: 14 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.

A flaw was found in Logback-classic. This path-traversal vulnerability allows a remote attacker to create and append log files outside the intended directory. This occurs because an unsanitized discriminator value, influenced by the attacker (for example, via an HTTP header), is used in a file path within the logging mechanism.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-cli-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-java-external-provider-rhel9Fix deferred
OpenShift Serverlessopenshift-serverless-1/kn-ekb-dispatcher-rhel9Fix deferred
OpenShift Serverlessopenshift-serverless-1/kn-ekb-receiver-rhel9Fix deferred
Red Hat Ceph Storage 6cephOut of support scope
Red Hat Ceph Storage 7cephFix deferred
Red Hat Ceph Storage 8cephFix deferred
Red Hat Ceph Storage 9cephOut of support scope
Red Hat Ceph Storage 9libarrowFix deferred
Red Hat Enterprise Linux 10apache-commons-loggingFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2516044ch.qos.logback/logback-classic: Logback-classic: Path traversal allows arbitrary log file creation

EPSS

Процентиль: 26%
0.00331
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

nvd
около 1 месяца назад

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.

debian
около 1 месяца назад

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (l ...

github
около 1 месяца назад

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.

EPSS

Процентиль: 26%
0.00331
Низкий

6.5 Medium

CVSS3