Executive brief
Logback is a popular logging framework used by Java applications to record system events. A vulnerability in how it processes configuration files could allow an attacker who already has high-level access to the system to execute malicious code. To be successful, the attacker must be able to modify the application's configuration files or environment variables, and the application must be using specific common Java libraries like Spring Framework.
Technical details
An Arbitrary Code Execution (ACE) vulnerability exists in logback-core versions up to 1.5.18 during the processing of conditional configuration files. The vulnerability is triggered when an attacker with existing high privileges (PR:H) modifies a logback configuration file or injects an environment variable pointing to a malicious configuration. Exploitation requires the Janino library and Spring Framework to be present on the application's classpath. This allows the attacker to execute arbitrary Java code through the configuration's conditional logic. The issue is addressed in versions 1.3.16 and 1.5.19.
Affected products
- QOS.CH Sarl Logback-core 0.9.20 to 1.5.18
Timeline
- 2025-10-01: disclosed
- 2025-10-01: advisory