SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks
Vulnerability Description
Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in XML configuration files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12801
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 7asecurity
More from QOS.CH Sarl
View All →Affected Vendor
QOS.CH Sarl
View all reports →