StackRadar

CVE-2024-12798

Medium

Advisory

Published 19 Dec 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
409
of 17,781 indexed, latest versions
Container images
383
deployed by those charts
Fix available
1 of 1
affected package

QOS.CH logback-core Expression Language Injection vulnerability

Carried by container images the latest versions of 409 of 17,781 indexed charts deploy, on 383 images.

Affected packageAffected versionsFixed inImages
logback-coremaven1.0.11, 1.0.13, 1.1.2, 1.1.3+30 more1.3.15, 1.5.13383
OSV records
GHSA-pr98-23f8-jwxv

Charts affected

409 by stars
ChartLatestAffected imagesRadar Score
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
logback-core@1.3.5
1.3.15
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
logback-core@1.2.10
1.3.15

Open the chart page →

9,397
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
logback-core@1.2.10
1.3.15

Open the chart page →

2,566
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
logback-core@1.2.3
1.3.15

Open the chart page →

5,460
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
logback-core@1.2.10
1.3.15

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
logback-core@1.2.10
1.3.15

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
logback-core@1.1.3
1.3.15

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
logback-core@1.1.3
1.3.15

Open the chart page →

22,665
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
logback-core@1.2.9
1.3.15

Open the chart page →

9,248
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-12798.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
logback-core@1.4.11
1.5.13

Open the chart page →

11,577

Container images carrying it

383 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
logback-core@1.4.14
1.5.13
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
logback-core@1.4.14
1.5.13
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
logback-core@1.2.3
1.3.15
1
amartinm82/planner:v2.01184353ff57b
logback-core@1.2.3
1.3.15
1
andrianrf/backoffice-be:latest6036614803d4
logback-core@1.2.12
1.3.15
1
andrianrf/bpjstk-service:latest46abe878d9d8
logback-core@1.2.3
1.3.15
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
logback-core@1.2.3
1.3.15
1
andrianrf/iso-client:latestba560086ce15
logback-core@1.2.3
1.3.15
1
andrianrf/iso-server:latest7da47f525c7d
logback-core@1.2.3
1.3.15
1
anguda/ant-media:2.5c435285fc241
logback-core@1.2.9
1.3.15
1
apache/camel-k:1.10.43bb13d14f64a
logback-core@1.2.11
1.3.15
1
apache/drill:1.21.11f96558fd292
logback-core@1.3.5
1.3.15
1
apacheignite/ignite:2.7.0d7deab68b8fa
logback-core@1.2.3
1.3.15
1
apache/iotdb:0.11.28647309f95d1
logback-core@1.1.11
1.3.15
1
apache/iotdb:0.13.3-nodeafa47bf1692a
logback-core@1.2.10
1.3.15
1
apache/nifi-registry:1.14.0090b7f87ec7f
logback-core@1.2.3
1.3.15
1
apache/nifi-registry:1.27.063b8e3e40742
logback-core@1.3.14
1.3.15
1
apache/nifi-registry:0.8.0974efa2f21da
logback-core@1.2.3
1.3.15
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
logback-core@1.2.3
1.3.15
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
logback-core@1.2.3
1.3.15
1
apachepulsar/pulsar:2.6.14db6ff0b4045
logback-core@1.2.3
1.3.15
1
apachepulsar/pulsar:3.0.79c9947de139d
logback-core@1.2.3
1.3.15
1
apachepulsar/pulsar:2.9.0d056c89b7131
logback-core@1.2.3
1.3.15
1
apachepulsar/pulsar:2.8.2d538416d5afe
logback-core@1.2.3
1.3.15
1
apache/ranger:2.7.076c176e8a0e4
logback-core@1.3.14
1.3.15
1
apache/rocketmq:5.3.0434d8398f996
logback-core@1.3.5
1.3.15
1
apache/rocketmq:4.9.35ac2a4e0f627
logback-core@1.2.10
1.3.15
1
apache/rocketmq-exporter:0.0.2c8fb51195444
logback-core@1.2.12
1.3.15
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
logback-core@1.2.3
1.3.15
1
apache/shenyu-admin:2.5.1e2be712fc4f4
logback-core@1.2.11
1.3.15
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
logback-core@1.2.11
1.3.15
1
apache/skywalking-ui:9.2.0295f1dc87d98
logback-core@1.2.11
1.3.15
1
apache/skywalking-ui:8.1.067d50e4deff4
logback-core@1.2.3
1.3.15
1
apache/skywalking-ui:8.9.180530f0308a5
logback-core@1.2.3
1.3.15
1
apimap/api:v1.8.11ae2b3ab00177
logback-core@1.2.11
1.3.15
1
aroralalit/student-producer:1.0.02a094f597b36
logback-core@1.2.12
1.3.15
1
arturisimo/planner:v1.0fff9de644941
logback-core@1.2.7
1.3.15
1
arturisimo/webapp-db-java:v2c95524e90b57
logback-core@1.2.10
1.3.15
1
assistiot/automated_configuration:latest23f195a7a26a
logback-core@1.2.11
1.3.15
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
logback-core@1.2.9
1.3.15
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
logback-core@1.2.11
1.3.15
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
logback-core@1.2.8
1.3.15
1
atomix/atomix:3.1.127738ff4f5c63
logback-core@1.1.2
1.3.15
1
audig/clamapi:2.1.62c3fe34ee430
logback-core@1.2.3
1.3.15
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
logback-core@1.2.10
1.3.15
1
beastob/url-shortener:1.0.299a49885ab33
logback-core@1.2.6
1.3.15
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
logback-core@1.2.3
1.3.15
1
biospheere/promcord:latest16d4fd269e66
logback-core@1.2.3
1.3.15
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
logback-core@1.2.9
1.3.15
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
logback-core@1.2.10
1.3.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.