CVE-2018-1285
CRITICALApache Log4net < 2.0.10 - XXE
Title source: ruleDescription
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Exploits (1)
nomisec
WORKING POC
1 stars
by alex-ermolaev · poc
https://github.com/alex-ermolaev/Log4NetSolarWindsSNMP-
References (17)
Scores
CVSS v3
9.8
EPSS
0.7207
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (12)
apache/log4net
< 2.0.10
fedoraproject/fedora
30
fedoraproject/fedora
31
fedoraproject/fedora
32
netapp/manageability_software_development_kit
netapp/snapcenter
nuget/log4net
0 - 2.0.10NuGet
oracle/application_testing_suite
13.3.0.1
oracle/hospitality_opera_5
5.5
oracle/hospitality_opera_5
5.6
... and 2 more
Published
May 11, 2020
Tracked Since
Feb 18, 2026