CVE-2026-19880
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green
Summary
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| QOS.CH Sarl | Logback-classic | 0.9.14 <= 1.6.2 | affected |
| QOS.CH Sarl | Logback-classic | 1.6.3 | unaffected |
Weaknesses
- CWE-22: CWE-22
Workarounds
Update to logack version 1.6.3 or later. This vulnerability requires SiftingAppender to be active as well as unsanitized data provided by an attacker that MDCDiscriminator makes use of.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.