Bug 2333370 (CVE-2024-12801)

Summary: CVE-2024-12801 logback-core: SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: abrianik, adupliak, anthomas, anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, brian.stansberry, bstansbe, caswilli, ccranfor, chazlett, chfoley, cmiranda, cmyers, csutherl, darran.lofthouse, dbruscin, dhanak, dkreling, dlofthou, dnakabaa, dosoudil, drichtar, dsoumis, ehelms, ehugonne, fmariani, ggainey, ggrzybek, gmalinko, gtanzill, ibek, istudens, ivassile, iweiss, janstey, jcantril, jclere, jkoops, jpasqual, jpechane, jpoth, jraez, jrokos, juwatts, jwon, kaycoth, kholdawa, kvanderr, kverlaen, lcouzens, mcarlett, mhulan, mnovotny, mosmerov, mposolda, mskarbek, msochure, msvehla, nmoumoul, nwallace, osousa, parichar, pcongius, pcreech, pdelbell, pdrozd, peholase, pesilva, pjindal, plodge, pmackay, pskopek, rchan, rguimara, rhel-process-autobot, rkieley, rmartinc, rmaucher, rojacob, rowaters, rstancel, rstepani, saroy, smaestri, smallamp, ssilvert, sthorger, swoodman, szappis, tasato, tcunning, thjenkin, tmalecek, tom.jenkinson, vdosoudi, vmuzikar, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A Server-Side Request Forgery (SSRF) vulnerability was found in Logback. This flaw allows a local attacker to forge requests by modifying XML configuration files to ignore external DTD files specified in DOCTYPE declarations, potentially exposing confidential or restricted data.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2024-12-19 17:01:29 UTC
Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.



The attacks involves the modification of DOCTYPE declaration inĀ  XML configuration files.