CVE-2018-1285

CRITICAL

Apache Log4net < 2.0.10 - XXE

Title source: rule

Description

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

Exploits (1)

nomisec WORKING POC 1 stars
by alex-ermolaev · poc
https://github.com/alex-ermolaev/Log4NetSolarWindsSNMP-

References (17)

Scores

CVSS v3 9.8
EPSS 0.4902
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-611
Status published

Affected Products (12)

apache/log4net < 2.0.10
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
oracle/application_testing_suite
oracle/hospitality_opera_5
oracle/hospitality_opera_5
oracle/hospitality_simphony
oracle/hospitality_simphony
netapp/manageability_software_development_kit
netapp/snapcenter
nuget/log4net < 2.0.10NuGet

Timeline

Published May 11, 2020
Tracked Since Feb 18, 2026