Code Injection in Logback - CVE-2024-12798

 

Code Injection in Logback - CVE-2024-12798

Published: January 24, 2025


Vulnerability identifier: #VU103289
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12798
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation in JaninoEventEvaluator extension when handling environment variables. A local user can inject specially crafted data into environment variables and execute arbitrary code with elevated privileges.


Affected software

Logback
Netcool Operations Insight
PowerVC
IBM Rational ClearCase
IBM Automation Decision Services
IBM Cloud Pak for Security
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Machine Learning on CP4D
Dell Secure Connect Gateway
IBM Cloud Pak for Business Automation
DataStax Hyper-Converged Database
Operations Analytics - Log Analysis
Cloud Pak for Network Automation
Tivoli Network Manager IP Edition
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
DevOps Code ClearCase
IBM Application Suite - IBM Asset Data Dictionary Component
Telco Service Design Configuration Designer
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
StreamSets Data Collector
Telco Network Function Virtualization Orchestrator
Business Automation Insights
Hybrid Cloud Observability
watsonx.data
IBM Cloud Pak System
Communications Service Catalog and Design
openSUSE Leap
openEuler
Oracle Hospitality Cruise Shipboard Property Management System
Orion Platform
logback-access
logback-help
logback
logback-examples
logback-javadoc
Red Hat Camel for Spring Boot

How to mitigate CVE-2024-12798

Install updates from vendor's website.

Logback - addressed in versions 1.3.15, 1.5.13
DataStax Hyper-Converged Database - update to 1.2.5
Operations Analytics - Log Analysis - update to 1.3.8.4
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
PowerVC - addressed in versions 2.2.1.2, 2.3.0
IBM Cloud Pak System - update to 2.3.6.0
Cloud Pak for Network Automation - update to 2.7.8
Tivoli Network Manager IP Edition - update to 4.2.0.22
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
IBM Rational ClearCase - update to 10.0.1.6
DevOps Code ClearCase - update to 11.0.0.6
Orion Platform - update to 2025.4.1
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
logback-access - update to 1.2.8-4
logback-help - update to 1.2.8-4
logback - update to 1.2.8-4
logback-examples - update to 1.2.8-4
logback-examples - update to 1.2.11-150200.3.10.1
logback-access - update to 1.2.11-150200.3.10.1
logback-javadoc - update to 1.2.11-150200.3.10.1
logback - update to 1.2.11-150200.3.10.1
IBM Cloud Pak for Security - update to 1.11.2.0
Telco Service Design Configuration Designer - update to 2.3.0
Red Hat Camel for Spring Boot - update to 4.8.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.9
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
IBM Watson Machine Learning on CP4D - update to 5.3.0
Dell Secure Connect Gateway - update to 5.28.00.14
StreamSets Data Collector - update to 7.0.0
Telco Network Function Virtualization Orchestrator - update to 7.3.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Business Automation Insights - addressed in versions 24.0.0.0.2, 24.0.1.0.1
Hybrid Cloud Observability - update to 2025.4.1

External References

Related Security Bulletins