Bug 2516044 (CVE-2026-19880)
| Summary: | CVE-2026-19880 ch.qos.logback/logback-classic: Logback-classic: Path traversal allows arbitrary log file creation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | amctagga, anthomas, aoconnor, aschwart, aszczucz, bniver, boliveir, csutherl, dhanak, drichtar, drosa, dsimansk, dsoumis, ehelms, flucifre, ggainey, gmalinko, gmeno, groman, gtanzill, janstey, jbuscemi, jclere, jpasqual, juwatts, jwon, kingland, mbenjamin, mdellweg, mhackett, mhulan, mnovotny, mposolda, nmoumoul, osousa, pcreech, pdelbell, pjindal, plodge, rchan, rhel-process-autobot, rjohnson, rmartinc, rmaucher, rstepani, sausingh, sdawley, smallamp, sostapov, ssilvert, sthorger, szappis, tmalecek, vereddy, vmuzikar, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Logback-classic. This path-traversal vulnerability allows a remote attacker to create and append log files outside the intended directory. This occurs because an unsanitized discriminator value, influenced by the attacker (for example, via an HTTP header), is used in a file path within the logging mechanism.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-14 14:41:16 UTC
|