Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25370
HistoryMay 11, 2020 - 3:38 a.m.

XML External Entities (XXE)

2020-05-1103:38:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
37

0.009 Low

EPSS

Percentile

82.8%

log4net is vulnerable to XML external entity attacks. External DTDs are enabled by default and allow attackers to perform XXE attacks using malicious XML data and documents.

References