Skip to content

Commit

Permalink
Merge pull request #5134 from github/pjfanning-GHSA-6v67-2wr5-gvf4
Browse files Browse the repository at this point in the history
  • Loading branch information
advisory-database[bot] authored Jan 3, 2025
2 parents 469f75b + 3a67cd9 commit 238132f
Showing 1 changed file with 8 additions and 5 deletions.
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v67-2wr5-gvf4",
"modified": "2024-12-20T15:12:53Z",
"modified": "2024-12-20T15:12:55Z",
"published": "2024-12-19T18:31:37Z",
"aliases": [
"CVE-2024-12801"
Expand All @@ -10,8 +10,8 @@
"details": "Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.\n \nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear"
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"
}
],
"affected": [
Expand All @@ -28,11 +28,14 @@
"introduced": "0"
},
{
"fixed": "1.5.13"
"fixed": "1.3.15"
}
]
}
]
],
"database_specific": {
"last_known_affected_version_range": "< 1.5.13"
}
}
],
"references": [
Expand Down

0 comments on commit 238132f

Please sign in to comment.