CVE-2018-1285 is a critical XML External Entity (XXE) vulnerability affecting Apache log4net versions prior to 2.0.10, impacting products from Apache, FedoraProject, NetApp, and Oracle. This flaw allows attackers to perform XXE-based attacks by providing malicious log4net configuration files, leading to potential compromise of confidentiality, integrity, and availability. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 97/100, it presents a significant risk. While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.10CPE matchmatch criteria | cpe:2.3:a:apache:log4net:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
13.3.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
Mar 23, 2022Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
Mar 23, 2022Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
Mar 23, 2022Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
Mar 23, 2022Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
Mar 23, 2022Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
Mar 23, 2022Improper Restriction of XML External Entity Reference in BVMS
Mar 16, 2022Improper Restriction of XML External Entity Reference in BVMS
Mar 16, 2022Improper Restriction of XML External Entity Reference in BVMS
Mar 16, 2022Improper Restriction of XML External Entity Reference in BVMS
Mar 16, 2022Improper Restriction of XML External Entity Reference in BVMS
Mar 16, 2022Improper Restriction of XML External Entity Reference in BVMS
Mar 16, 2022XML External Entity attack in log4net
Jan 29, 2021