PT-2020-5531 · Apache+2 · Log4Net+2

Published

2020-05-11

·

Updated

2025-06-03

·

CVE-2018-1285

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache log4net versions prior to 2.0.10
Description The issue is related to errors in restricting XML links to external objects (XXE) in the log4net logging library on the .NET Framework platform. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. This could enable XXE-based attacks in applications that accept arbitrary configuration files from users.
Recommendations For Apache log4net versions prior to 2.0.10, update to version 2.0.10 or later to resolve the issue. As a temporary workaround, consider disabling the parsing of XML external entities when handling log4net configuration files to minimize the risk of exploitation. Restrict access to log4net configuration files to prevent attackers from providing malicious input.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2021-01050
CVE-2018-1285
DLA-2211-1
GHSA-2CWJ-8CHV-9PP9
MGASA-2020-0233
OPENSUSE-SU-2024:12311-1
ROSA-SA-2023-2169
USN-4699-1

Affected Products

Linuxmint
Ubuntu
Log4Net