CVE-2024-12801

Severity CVSS v4.0:
LOW
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
19/12/2024
Last modified:
15/04/2026

Description

Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to <br /> forge requests by compromising logback configuration files in XML.<br /> <br /> <br /> <br /> The attacks involves the modification of DOCTYPE declaration in  XML configuration files.