CVE-2018-1285 PUBLISHED

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

EPSS 49.02% · 97.7th percentile

Risk Scores

EPSS Score
49.02%
97.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlog4net1.2.10+dfsg-7, 0
Ubuntu:18.04:LTSlog4net1.2.10+dfsg-7, 0
Ubuntu:22.04:LTSlog4net1.2.10+dfsg-8, 0
Ubuntu:16.04:LTSlog4net1.2.10+dfsg-6, 0, 1.2.10+dfsg-7

Timeline

References

Open in Interactive Console →