Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Autodesk Autocad | — | Update Autodesk AutoCAD to the latest version for Windows and macOS. | Jul 22, 2025 | Jan 12, 2022 |
| Debian | — | Upgrade log4net | May 19, 2020 | May 11, 2020 |
| Ubuntu | — | Upgrade liblog4net1.2-cil | Jan 20, 2021 | May 11, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub