This update for logback fixes the following issues:
* CVE-2024-12798: Fixed arbitrary code execution via JaninoEventEvaluator
(bsc#1234742)
* CVE-2024-12801: Fixed Server-Side Request Forgery in SaxEventRecorder
(bsc#1234743)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-72=1
* openSUSE Leap 15.6 (noarch)
* logback-examples-1.2.11-150200.3.10.1
* logback-1.2.11-150200.3.10.1
* logback-javadoc-1.2.11-150200.3.10.1
* logback-access-1.2.11-150200.3.10.1
* bsc#1234742
* bsc#1234743
## References:
* https://www.suse.com/security/cve/CVE-2024-12798.html
* https://www.suse.com/security/cve/CVE-2024-12801.html
* https://bugzilla.suse.com/show_bug.cgi?id=1234742
* https://bugzilla.suse.com/show_bug.cgi?id=1234743
Get the latest Linux and open source security news straight to your inbox.