VDB
Sign up
CRITICAL9.8

GHSA-2cwj-8chv-9pp9

XML External Entity attack in log4net

Quick fix

GHSA-2cwj-8chv-9pp9 — log4net: upgrade to the fixed version with the command below.

dotnet add package log4net --version 2.0.10

Details

Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/log4net
Introduced in: 0Fixed in: 2.0.10
Fixdotnet add package log4net --version 2.0.10

References