CVE-2025-54812 is an Improper Output Neutralization vulnerability in Apache Log4cxx versions prior to 1.5.0, specifically impacting HTMLLayout. If untrusted data is used for logger names, an attacker could inject HTML or JavaScript into generated log files, potentially leading to Cross-Site Scripting (XSS) when a user views the logs. The CVSS score is 5.4 MEDIUM, indicating a network attack vector with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. While the EPSS and FAUCET scores are low, suggesting a low likelihood of exploitation, there is no known active exploitation, public exploit code, or significant community discussion beyond a single mention and article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:apache:log4cxx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.