CVE-2018-1285
CRITICALApache Log4net < 2.0.10 - XXE
Title source: ruleDescription
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Exploits (1)
nomisec
WORKING POC
1 stars
by alex-ermolaev · poc
https://github.com/alex-ermolaev/Log4NetSolarWindsSNMP-
References (17)
Scores
CVSS v3
9.8
EPSS
0.4902
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-611
Status
published
Affected Products (12)
apache/log4net
< 2.0.10
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
oracle/application_testing_suite
oracle/hospitality_opera_5
oracle/hospitality_opera_5
oracle/hospitality_simphony
oracle/hospitality_simphony
netapp/manageability_software_development_kit
netapp/snapcenter
nuget/log4net
< 2.0.10NuGet
Timeline
Published
May 11, 2020
Tracked Since
Feb 18, 2026