CVE-2025-54813
published 2025-08-22CVE-2025-54813: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.21%
64.9th percentile
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx.
When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them.
This issue affects Apache Log4cxx: before 1.5.0.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4cxx | < 1.5.0 | 1.5.0 |
| apache | log4cxx | >= 0 < 0.11.0-2+deb11u1 | 0.11.0-2+deb11u1 |
| apache | log4cxx | >= 0 < 1.0.0-1+deb12u1 | 1.0.0-1+deb12u1 |
| apache | log4cxx | >= 0 < 1.4.0-1+deb13u1 | 1.4.0-1+deb13u1 |
| apache | log4cxx | >= 0 < 1.4.0-1.1 | 1.4.0-1.1 |
| apache | logging | — | — |
| apache_software_foundation | apache_log4cxx | >= 0.11.0 < 1.5.0 | 1.5.0 |
| debian | log4cxx | < log4cxx 1.0.0-1+deb12u1 (bookworm) | log4cxx 1.0.0-1+deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.3MEDIUM
vendor_apache6.3
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-log4cxx: Log4cxx: Improper JSON Output Neutralization
vendor_redhat·2025-08-22·CVSS 6.3
CVE-2025-54813 [MEDIUM] CWE-117 apache-log4cxx: Log4cxx: Improper JSON Output Neutralization
apache-log4cxx: Log4cxx: Improper JSON Output Neutralization
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx.
When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them.
This issue affects Apache Log4cxx: before 1.5.0.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.
A flaw was found in apache-log4cxx. When utilizing JSONLayout, the component fails to properly escape certain payload bytes, allowing attacker-supplied messages containing specific non-printable charac
Debian
CVE-2025-54813: log4cxx - Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When u...
vendor_debian·2025·CVSS 6.3
CVE-2025-54813 [MEDIUM] CVE-2025-54813: log4cxx - Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When u...
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them. This issue affects Apache Log4cxx: before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 1.0.0-1+deb12u1)
bullseye: resolved (fixed in 0.11.0-2+deb11u1)
forky: resolved (fixed in 1.4.0-1.1)
sid: resolved (fixed in 1.4.0-1.1)
trixie: resolved (fixed in 1.4.0-1+deb13u1)
Apache
Apache logging: CVE-2025-54813
vendor_apache·CVSS 6.3
CVE-2025-54813 Apache logging: CVE-2025-54813
Apache logging: CVE-2025-54813
Summary Improper escaping with JSONLayout CVSS 4.x Score & Vector 6.3 MEDIUM (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N) Components affected Log4cxx Versions affected [0.11.0, 1.5.0) Versions fixed 1.5.0
Severity: moderate
Affected versions: 1.5.0
GHSA
GHSA-68p3-h5c2-5hcr: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx
ghsa_unreviewed·2025-08-22
CVE-2025-54813 [MEDIUM] CWE-117 GHSA-68p3-h5c2-5hcr: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx.
When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them.
This issue affects Apache Log4cxx: before 1.5.0.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.
OSV
CVE-2025-54813: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx
osv·2025-08-22·CVSS 6.3
CVE-2025-54813 [MEDIUM] CVE-2025-54813: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them. This issue affects Apache Log4cxx: before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-22
Published