{"id":"UBUNTU-CVE-2024-12801","details":"Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in  XML configuration files.","modified":"2026-01-20T18:12:04.384188Z","published":"2024-12-19T17:15:00Z","upstream":["CVE-2024-12801"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-12801"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-12801"},{"type":"REPORT","url":"https://logback.qos.ch/news.html#1.5.13"}],"affected":[{"package":{"name":"logback","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/logback@1:1.1.3-2ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.1.3-2","1:1.1.3-2ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblogback-java","binary_version":"1:1.1.3-2ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-12801.json"}},{"package":{"name":"logback","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/logback@1:1.2.3-2ubuntu1~18.04.1+esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.1.9-4","1:1.1.9-5","1:1.2.3-2","1:1.2.3-2ubuntu1~18.04.1","1:1.2.3-2ubuntu1~18.04.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:1.2.3-2ubuntu1~18.04.1+esm1","binary_name":"liblogback-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-12801.json"}},{"package":{"name":"logback","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/logback@1:1.2.3-5ubuntu0.1~esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.2.3-5","1:1.2.3-5ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblogback-java","binary_version":"1:1.2.3-5ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-12801.json"}},{"package":{"name":"logback","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/logback@1:1.2.10-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.2.3-6","1:1.2.7-1","1:1.2.8-1","1:1.2.9-1","1:1.2.10-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:1.2.10-1","binary_name":"liblogback-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-12801.json"}},{"package":{"name":"logback","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/logback@1:1.2.11-5?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.2.11-3","1:1.2.11-4","1:1.2.11-5"],"ecosystem_specific":{"binaries":[{"binary_name":"liblogback-java","binary_version":"1:1.2.11-5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-12801.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear"},{"type":"Ubuntu","score":"medium"}]}