PT-2025-34482 · Apache+2 · Apache Log4Cxx+2

Published

2025-01-01

·

Updated

2025-11-05

·

CVE-2025-54813

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Apache Log4cxx versions prior to 1.5.0
Description: The software contains an improper output neutralization issue for logs. When using JSONLayout, not all payload bytes are properly escaped. Attackers can supply messages containing non-printable characters that will be passed along and written as part of the JSON message, potentially preventing applications consuming these logs from correctly interpreting the information.
Recommendations: Upgrade to version 1.5.0.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-13812
CVE-2025-54813
DLA-4322-1

Affected Products

Apache Log4Cxx
Debian
Red Os