CVE-2018-1285: Apache LOG4NET
Critical severity, CVSS 9.8. EPSS: 17.4% chance of exploitation in the next 30 days.
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Affected products
- Apache LOG4NET: before 2.0.10 (fixed in 2.0.10)
- Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
- Netapp Manageability Software Development Kit: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Oracle Application Testing Suite: version 13.3.0.1 only
- Oracle Hospitality Opera 5: version 5.5 only; version 5.6 only
- Oracle Hospitality Simphony: version 18.2.7.2 only; version 19.1.3 only
Published 2020-05-11. Last modified 2026-06-17.