cbcvebase.
CVE-2018-1285
published 2020-05-11

CVE-2018-1285: Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in…

PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.37%
96.8th percentile
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachelog4net< 2.0.102.0.10
apachelog4net>= 0 < 1.2.10+dfsg-81.2.10+dfsg-8
apachelog4net>= 0 < 1.2.10+dfsg-81.2.10+dfsg-8
apachelog4net>= 0 < 2.0.102.0.10
debianlog4net< log4net 1.2.10+dfsg-8 (bullseye)log4net 1.2.10+dfsg-8 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
oracleapplication_testing_suite
oraclehospitality_opera_5
oraclehospitality_opera_5
oraclehospitality_simphony
oraclehospitality_simphony
questkace_desktop_authority>= 10.0 < 11.211.2

Detection & IOCsextracted from sources · hover to see the quote

  • Target applications that parse attacker-controlled log4net configuration files — XXE is triggered during XML parsing of those config files
  • Flag inbound HTTP requests delivering or referencing log4net configuration files to vulnerable endpoints (remote exploit, no auth required, low complexity)
  • Monitor for XXE-based out-of-band data exfiltration (DNS/HTTP callbacks) originating from processes hosting log4net on affected versions prior to 2.0.10
  • Quest KACE Desktop Authority before 11.2 is a known affected product — monitor for suspicious log4net config file writes or replacements on those hosts
  • Rockwell Automation FactoryTalk Historian ThingWorx (95057C-FTHTWXCT11) v4.02.00 and prior are affected ICS products — alert on unexpected XML config file modifications in those environments
  • ·Vulnerability only manifests when an attacker can supply or modify the log4net configuration file — exploitation requires that attack surface to be exposed
  • ·No known public exploitation specifically targeting this vulnerability has been reported to CISA as of the advisory date
  • ·Fixed version threshold is log4net 2.0.10; Debian packages fixed in 1.2.10+dfsg-8 — ensure version checks account for both upstream and distro-repackaged version strings

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.