openSUSE: 2025:0072-1 important: logback Advisory Security Update
Description
This update for logback fixes the following issues: * CVE-2024-12798: Fixed arbitrary code execution via JaninoEventEvaluator (bsc#1234742) * CVE-2024-12801: Fixed Server-Side Request Forgery in SaxEventRecorder (bsc#1234743)
Patch
## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-72=1
Package List
* openSUSE Leap 15.6 (noarch) * logback-examples-1.2.11-150200.3.10.1 * logback-1.2.11-150200.3.10.1 * logback-javadoc-1.2.11-150200.3.10.1 * logback-access-1.2.11-150200.3.10.1
References
* bsc#1234742 * bsc#1234743 ## References: * https://www.suse.com/security/cve/CVE-2024-12798.html * https://www.suse.com/security/cve/CVE-2024-12801.html * https://bugzilla.suse.com/show_bug.cgi?id=1234742 * https://bugzilla.suse.com/show_bug.cgi?id=1234743