dec 16, 2021 - CVE-2021-42550
CVSSv3: N/A
logback 1.2.7 conf access allows for LDAP code-exec
Description:
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
Added to timeline:
Date:
~ 2 years and 5 months ago