In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
History

Tue, 24 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Title RCE from attacker with configuration edit priviledges through JNDI lookup RCE from attacker with configuration edit priviledges through JNDI lookup

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.02163}

epss

{'score': 0.03447}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01715}

epss

{'score': 0.02163}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2021-12-16T00:00:00.000Z

Updated: 2024-08-04T03:38:49.194Z

Reserved: 2021-10-15T00:00:00.000Z

Link: CVE-2021-42550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-16T19:15:08.297

Modified: 2024-11-21T06:27:47.313

Link: CVE-2021-42550

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-12-16T00:00:00Z

Links: CVE-2021-42550 - Bugzilla