---
title: "CVE-2024-12801\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-12801?format=md
keywords: index, follow
---

# CVE-2024-12801

Publication date 19 December 2024

Last updated 17 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback
version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an
attacker to
forge requests by compromising logback configuration files in XML.
The attacks involves the modification of DOCTYPE declaration in  XML
configuration files.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2024-12801?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| logback | 25.04 plucky | Ignored end of life, was ignored [changes too intrusive] |
| 24.10 oracular | Ignored end of life, was ignored [changes too intrusive] |
| 24.04 LTS noble | Ignored changes too intrusive |
| 22.04 LTS jammy | Ignored changes too intrusive |
| 20.04 LTS focal | Ignored end of standard support, was needs-triage |
| 18.04 LTS bionic | Ignored changes too intrusive |
| 16.04 LTS xenial | Ignored end of ESM support, was ignored [changes too intrusive] |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2024-12801?format=md#patch-details)

## Notes

---

### [john-breton](https://launchpad.net/~john-breton)

Backporting the fix from 1.5.13 to 1.2.X involved breaking
changes to the code, the patch is infeasible as is.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| logback | * Upstream:   [5f05041](https://github.com/qos-ch/logback/commit/5f05041cba4c4ac0a62748c5c527a2da48999f2d) |

## Severity score breakdown

CVSS version:
CVSS v4.0

**Base score**

2.4 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | Low |
  | User interaction | Passive |
  | Vulnerable system - Confidentiality impact | Low |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | High |
  | Subsequent system - Integrity impact | High |
  | Subsequent system - Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 2.4 · Low |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-12801)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-12801)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-12801)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-12801)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-12801>
* <https://logback.qos.ch/news.html#1.5.13>
