Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2024-12798

Disclosure Date: December 19, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core

  upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
  attacker to execute arbitrary code by compromising an existing
  logback configuration file or by injecting an environment variable
  before program execution.

Malicious logback configuration files can allow the attacker to execute
arbitrary code using the JaninoEventEvaluator extension.

A successful attack requires the user to have write access to a
configuration file. Alternatively, the attacker could inject a malicious
environment variable pointing to a malicious configuration file. In both
cases, the attack requires existing privilege.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

Products

Additional Info

Technical Analysis