Description
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2cwj-8chv-9pp9 | XML External Entity attack in log4net |
Ubuntu USN |
USN-4699-1 | Apache Log4net vulnerability |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T03:59:37.654Z
Reserved: 2017-12-07T00:00:00.000Z
Link: CVE-2018-1285
No data.
Status : Modified
Published: 2020-05-11T17:15:10.923
Modified: 2024-11-21T03:59:32.683
Link: CVE-2018-1285
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA
Ubuntu USN