Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 NuGet

XML External Entity attack in log4net

GHSA-2cwj-8chv-9pp9 · CVE-2018-1285

Published · Modified

Description

Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes