PT-2026-51676 · Janino+1 · Janino+1
CVSS v4.0
7.0
High
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:X/RE:M/U:Green |
Name of the Vulnerable Software and Affected Versions
logback-core versions prior to 1.5.35
Description
An arbitrary code execution issue exists in the conditional configuration file processing of Java applications. An attacker can execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution, which bypasses protections against previous similar issues. This attack requires the Janino library to be present on the user's class path and requires the attacker to have existing privileges, such as write access to a configuration file or the ability to inject a malicious environment variable pointing to a malicious configuration file.
Recommendations
Update to version 1.5.35 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Janino
Logback-Core