CVE-2018-1285

CRITICAL

Apache Log4net < 2.0.10 - XXE

Title source: rule

Description

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

Exploits (1)

nomisec WORKING POC 1 stars
by alex-ermolaev · poc
https://github.com/alex-ermolaev/Log4NetSolarWindsSNMP-

References (17)

Scores

CVSS v3 9.8
EPSS 0.7207
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (12)
apache/log4net < 2.0.10
fedoraproject/fedora 30
fedoraproject/fedora 31
fedoraproject/fedora 32
netapp/manageability_software_development_kit
netapp/snapcenter
nuget/log4net 0 - 2.0.10NuGet
oracle/application_testing_suite 13.3.0.1
oracle/hospitality_opera_5 5.5
oracle/hospitality_opera_5 5.6
... and 2 more
Published May 11, 2020
Tracked Since Feb 18, 2026