CVE-2024-12801: SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks

2.4 CVSS

Description

Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to
forge requests by compromising logback configuration files in XML.

The attacks involves the modification of DOCTYPE declaration in  XML configuration files.

Classification

CVE ID: CVE-2024-12801

CVSS Base Severity: LOW

CVSS Base Score: 2.4

Affected Products

Vendor: QOS.CH Sarl

Product: logback

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://logback.qos.ch/news.html#1.5.13

Timeline