CVE-2021-42550

Source
https://cve.org/CVERecord?id=CVE-2021-42550
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-42550.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-42550
Aliases
Downstream
Related
Published
2021-12-16T19:15:08.297Z
Modified
2026-05-28T04:08:42.581450989Z
Severity
  • 6.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "siemens:sinec_nms",
            "extracted_events": [
                {
                    "fixed": "1.0.3"
                }
            ],
            "cpes": [
                "cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "qos:logback",
            "extracted_events": [
                {
                    "last_affected": "1.3.0-alpha1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:qos:logback:1.3.0:alpha1:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "redhat:satellite",
            "extracted_events": [
                {
                    "last_affected": "6.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/qos-ch/logback

Affected ranges

Type
GIT
Repo
https://github.com/qos-ch/logback
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.2.7"
        },
        {
            "last_affected": "1.3.0-alpha0"
        },
        {
            "last_affected": "1.3.0-alpha10"
        },
        {
            "last_affected": "1.3.0-alpha2"
        },
        {
            "last_affected": "1.3.0-alpha3"
        },
        {
            "last_affected": "1.3.0-alpha4"
        },
        {
            "last_affected": "1.3.0-alpha5"
        },
        {
            "last_affected": "1.3.0-alpha6"
        },
        {
            "last_affected": "1.3.0-alpha7"
        },
        {
            "last_affected": "1.3.0-alpha8"
        },
        {
            "last_affected": "1.3.0-alpha9"
        }
    ],
    "cpe": [
        "cpe:2.3:a:qos:logback:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha0:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha10:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha2:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha3:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha4:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha5:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha6:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha7:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha8:*:*:*:*:*:*",
        "cpe:2.3:a:qos:logback:1.3.0:alpha9:*:*:*:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

Other
list
release_0.*
release_0.9.19
v0.*
v0.9.18
v0.9.20
v1.*
v1.0.10
v_0.*
v_0.9.21
v_0.9.22
v_0.9.23
v_0.9.24
v_0.9.25
v_0.9.26
v_0.9.27
v_0.9.28
v_0.9.29
v_0.9.30
v_1.*
v_1.0.0
v_1.0.1
v_1.0.11
v_1.0.2
v_1.0.3
v_1.0.4
v_1.0.5
v_1.0.6
v_1.0.7
v_1.0.8
v_1.0.9
v_1.1.0
v_1.1.1
v_1.1.10
v_1.1.4
v_1.1.5
v_1.1.6
v_1.1.7
v_1.1.8
v_1.2.0
v_1.2.1
v_1.2.2
v_1.2.3
v_1.2.4
v_1.2.5
v_1.2.6
v_1.2.7
v_1.3.0-alpha0
v_1.3.0-alpha10
v_1.3.0-alpha2
v_1.3.0-alpha3
v_1.3.0-alpha4
v_1.3.0-alpha5
v_1.3.0-alpha6
v_1.3.0-alpha7
v_1.3.0-alpha8
v_1.3.0-alpha9
v_1.8.0-alpha1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-42550.json"