{"id":"GHSA-668q-qrv7-99fm","summary":"Deserialization of Untrusted Data in logback","details":"In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.","aliases":["CVE-2021-42550"],"modified":"2024-02-14T05:31:45.676809Z","published":"2021-12-17T20:00:50Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-12-17T19:25:11Z","nvd_published_at":"2021-12-16T19:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42550"},{"type":"WEB","url":"https://github.com/qos-ch/logback/commit/87291079a1de9369ac67e20dc70a8fdc7cc4359c"},{"type":"WEB","url":"https://github.com/qos-ch/logback/commit/ef4fc4186b74b45ce80d86833820106ff27edd42"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf"},{"type":"WEB","url":"https://github.com/cn-panda/logbackRceDemo"},{"type":"PACKAGE","url":"https://github.com/qos-ch/logback"},{"type":"WEB","url":"https://github.com/qos-ch/logback/blob/1502cba4c1dfd135b2e715bc0cf80c0045d4d128/logback-site/src/site/pages/news.html"},{"type":"WEB","url":"https://jira.qos.ch/browse/LOGBACK-1591"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20211229-0001"},{"type":"WEB","url":"http://logback.qos.ch/news.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Jul/11"}],"affected":[{"package":{"name":"ch.qos.logback:logback-core","ecosystem":"Maven","purl":"pkg:maven/ch.qos.logback/logback-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9"}]}],"versions":["0.2.5","0.3","0.5","0.6","0.7","0.7.1","0.8","0.8.1","0.9","0.9.1","0.9.10","0.9.11","0.9.12","0.9.13","0.9.14","0.9.15","0.9.16","0.9.17","0.9.18","0.9.19","0.9.2","0.9.20","0.9.21","0.9.22","0.9.23","0.9.24","0.9.25","0.9.26","0.9.27","0.9.28","0.9.29","0.9.3","0.9.30","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.10","1.1.11","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.4-groovyless","1.2.5","1.2.6","1.2.7","1.2.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-668q-qrv7-99fm/GHSA-668q-qrv7-99fm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}