CVE-2021-42550

MEDIUM6.6EPSS 2.7%

Deserialization of Untrusted Data in logback

Published: 12/17/2021Modified: 4/28/2026

Description

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.6CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

References (13)