PT-2020-5531 · Apache+2 · Log4Net+2
Published
2020-05-11
·
Updated
2025-06-03
·
CVE-2018-1285
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache log4net versions prior to 2.0.10
Description
The issue is related to errors in restricting XML links to external objects (XXE) in the log4net logging library on the .NET Framework platform. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. This could enable XXE-based attacks in applications that accept arbitrary configuration files from users.
Recommendations
For Apache log4net versions prior to 2.0.10, update to version 2.0.10 or later to resolve the issue. As a temporary workaround, consider disabling the parsing of XML external entities when handling log4net configuration files to minimize the risk of exploitation. Restrict access to log4net configuration files to prevent attackers from providing malicious input.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Log4Net