PT-2026-72028 · Unknown · Logback-Classic
CVE-2026-19880
·
Published
2026-08-14
·
Updated
2026-08-14
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green |
Name of the Vulnerable Software and Affected Versions
Logback-classic versions 0.9.14 through 1.6.2
Description
A path-traversal issue exists in the
logback-classic module. An MDC-based discriminator value is passed unsanitized into a nested FileAppender path. This allows an attacker who can influence the MDC value, such as through an HTTP header, to create and append log files outside of the intended directory. MDC (Mapped Diagnostic Context) is a mechanism used to track information across a thread of execution.Recommendations
Update Logback-classic to a version later than 1.6.2.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logback-Classic