Lucene search

K
osvGoogleOSV:GHSA-668Q-QRV7-99FM
HistoryDec 17, 2021 - 8:00 p.m.

Deserialization of Untrusted Data in logback

2021-12-1720:00:50
Google
osv.dev
26

0.016 Low

EPSS

Percentile

87.3%

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.