CVE-2018-1285

Severity
9.8CRITICAL
EPSS
49.0%
top 2.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateOct 15

Description

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

NVDapache/log4net< 2.0.10
CVEListV5apache_log4netApache log4net up to 2.0.8
NuGetlog4net< 2.0.10
Debianlog4net< 1.2.10+dfsg-8+1

Also affects: Fedora 30, 31, 32

Patches

🔴Vulnerability Details

4
GHSA
XML External Entity attack in log4net2021-01-29
OSV
XML External Entity attack in log4net2021-01-29
OSV
CVE-2018-1285: Apache log4net versions before 22020-05-11
CVEList
CVE-2018-1285: Apache log4net versions before 22020-05-11

📋Vendor Advisories

6
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache log4net) — CVE-2018-12852022-10-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache log4net) — CVE-2018-12852022-04-15
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) — CVE-2018-12852021-04-15
Ubuntu
Apache Log4net vulnerability2021-01-19
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) — CVE-2018-12852021-01-15

💬Community

4
Bugzilla
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [fedora-all]2020-05-15
Bugzilla
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [epel-all]2020-05-15
Bugzilla
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users2020-05-14
Bugzilla
CVE-2018-1274 spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service2018-04-11