CVE-2024-12801
Severity CVSS v4.0:
LOW
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
19/12/2024
Last modified:
15/04/2026
Description
Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 on the Java platform, allows an attacker to <br />
forge requests by compromising logback configuration files in XML.<br />
<br />
<br />
<br />
The attacks involves the modification of DOCTYPE declaration in XML configuration files.



