QOS.CH Sarl Logback-classic for Java(logback-classic 模块)中存在路径遍历漏洞。具体而言,基于 MDC(Mapped Diagnostic Context)的判别器值未经过消毒处理,直接嵌套到 FileAppender 的路径中。攻击者若能影响该 MDC 值(例如通过 HTTP 请求头),即可在预期目录之外创建和追加日志文件。 该漏洞影响 Logback-classic 从 0.9.14 到 1.6.4 的所有版本。此漏洞与 CVE-2026-19880 类似,但
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| QOS.CH Sarl | Logback-classic | 0.9.14≤ 1.6.4 |
affected |
1.6.5 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QOS.CH Sarl | Logback-classic | 0.9.14 ~ 1.6.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet