PT-2025-34481 · Apache+2 · Apache Log4Cxx+2

Published

2023-05-08

·

Updated

2025-11-05

·

CVE-2025-54812

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Log4cxx versions prior to 1.5.0
Description: Apache Log4cxx contains an Improper Output Neutralization for Logs issue. When using HTMLLayout, logger names are not properly escaped when writing to an HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could inject HTML or Javascript, potentially leading to cross-site scripting (XSS) when a user opens the generated HTML log file in their browser. This requires the following sequence: Log4cxx is configured to use HTMLLayout, the logger name comes from an untrusted string, a logger with the compromised name logs a message, and a user opens the generated HTML log file.
Recommendations: Upgrade to version 1.5.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-13810
BDU:2025-13811
BDU:2025-13812
CVE-2025-54812
DLA-4322-1
OPENSUSE-SU-2025:15549-1

Affected Products

Apache Log4Cxx
Debian
Red Os