CVE-2018-1285: Apache LOG4NET

Critical severity, CVSS 9.8. EPSS: 17.4% chance of exploitation in the next 30 days.

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

Affected products

  • Apache LOG4NET: before 2.0.10 (fixed in 2.0.10)
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Netapp Manageability Software Development Kit: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Oracle Application Testing Suite: version 13.3.0.1 only
  • Oracle Hospitality Opera 5: version 5.5 only; version 5.6 only
  • Oracle Hospitality Simphony: version 18.2.7.2 only; version 19.1.3 only

Published 2020-05-11. Last modified 2026-06-17.