Lucene search

K
osvGoogleOSV:GHSA-2CWJ-8CHV-9PP9
HistoryJan 29, 2021 - 7:47 p.m.

XML External Entity attack in log4net

2021-01-2919:47:23
Google
osv.dev
85

0.009 Low

EPSS

Percentile

82.8%

Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.

References