CVE-2018-1285
Severity
9.8CRITICAL
EPSS
49.0%
top 2.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateOct 15
Description
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages7 packages
Also affects: Fedora 30, 31, 32
Patches
🔴Vulnerability Details
4📋Vendor Advisories
6Oracle▶
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache log4net) — CVE-2018-1285↗2022-10-15
Oracle▶
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache log4net) — CVE-2018-1285↗2022-04-15
Oracle▶
Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) — CVE-2018-1285↗2021-04-15
Oracle▶
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) — CVE-2018-1285↗2021-01-15
💬Community
4Bugzilla▶
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [fedora-all]↗2020-05-15
Bugzilla▶
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [epel-all]↗2020-05-15
Bugzilla▶
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users↗2020-05-14
Bugzilla▶
CVE-2018-1274 spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service↗2018-04-11