CVE-2024-12801
Publication date 19 December 2024
Last updated 26 June 2025
Ubuntu priority
Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in XML configuration files.
Status
Package | Ubuntu Release | Status |
---|---|---|
logback | 25.04 plucky | Ignored changes too intrusive |
24.10 oracular | Ignored changes too intrusive | |
24.04 LTS noble | Ignored changes too intrusive | |
22.04 LTS jammy | Ignored changes too intrusive | |
20.04 LTS focal | Ignored changes too intrusive | |
18.04 LTS bionic | Ignored changes too intrusive | |
16.04 LTS xenial | Ignored changes too intrusive |
Notes
john-breton
Backporting the fix from 1.5.13 to 1.2.X involved breaking changes to the code, the patch is infeasible as is.