8.5

CVE-2021-42550

Exploit

RCE from attacker with configuration edit priviledges through JNDI lookup

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qos ≫ Logback Version <= 1.2.7
Qos ≫ Logback Version 1.3.0 Update alpha0
Qos ≫ Logback Version 1.3.0 Update alpha1
Qos ≫ Logback Version 1.3.0 Update alpha10
Qos ≫ Logback Version 1.3.0 Update alpha2
Qos ≫ Logback Version 1.3.0 Update alpha3
Qos ≫ Logback Version 1.3.0 Update alpha4
Qos ≫ Logback Version 1.3.0 Update alpha5
Qos ≫ Logback Version 1.3.0 Update alpha6
Qos ≫ Logback Version 1.3.0 Update alpha7
Qos ≫ Logback Version 1.3.0 Update alpha8
Qos ≫ Logback Version 1.3.0 Update alpha9
Redhat ≫ Satellite Version 6.0
Netapp ≫ Cloud Manager Version -
Siemens ≫ Sinec Nms Version < 1.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.44% 0.902
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
vulnerability@ncsc.ch 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2022/Jul/11
Third Party Advisory
Mailing List
http://logback.qos.ch/news.html
Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf
Third Party Advisory
https://github.com/cn-panda/logbackRceDemo
Third Party Advisory
Exploit
https://jira.qos.ch/browse/LOGBACK-1591
Patch
Third Party Advisory
Exploit
Issue Tracking
https://security.netapp.com/advisory/ntap-20211229-0001/
Third Party Advisory