Security update for logback
Announcement ID: | SUSE-SU-2025:0072-1 |
---|---|
Release Date: | 2025-01-10T18:33:38Z |
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves two vulnerabilities can now be installed.
Description:
This update for logback fixes the following issues:
- CVE-2024-12798: Fixed arbitrary code execution via JaninoEventEvaluator (bsc#1234742)
- CVE-2024-12801: Fixed Server-Side Request Forgery in SaxEventRecorder (bsc#1234743)
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-72=1
Package List:
-
openSUSE Leap 15.6 (noarch)
- logback-examples-1.2.11-150200.3.10.1
- logback-1.2.11-150200.3.10.1
- logback-javadoc-1.2.11-150200.3.10.1
- logback-access-1.2.11-150200.3.10.1