cbcvebase.
CVE-2018-1285
published 2020-05-11

CVE-2018-1285: Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachelog4net< 2.0.102.0.10
apachelog4net>= 0 < 1.2.10+dfsg-81.2.10+dfsg-8
apachelog4net>= 0 < 1.2.10+dfsg-81.2.10+dfsg-8
apachelog4net>= 0 < 2.0.102.0.10
debianlog4net< log4net 1.2.10+dfsg-8 (bullseye)log4net 1.2.10+dfsg-8 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
oracleapplication_testing_suite
oraclehospitality_opera_5
oraclehospitality_opera_5
oraclehospitality_simphony
oraclehospitality_simphony
questkace_desktop_authority>= 10.0 < 11.211.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL