VDB
Sign up
MEDIUM

GHSA-h383-gmxw-35v2

Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

Quick fix

GHSA-h383-gmxw-35v2 — org.apache.logging.log4j:log4j-1.2-api: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.25.4</version> for org.apache.logging.log4j:log4j-1.2-api

Details

The `Log4j1XmlLayout` from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.

Two groups of users are affected:

* Those using `Log4j1XmlLayout` directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with `org.apache.log4j.xml.XMLLayout` specified as the layout class.

Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version `2.25.4`, which corrects this issue.

> [!NOTE] > The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the > [Log4j 1 to Log4j 2 migration guide](https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html), and specifically the section on eliminating reliance on the bridge.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.logging.log4j:log4j-1.2-api
Introduced in: 2.7Fixed in: 2.25.4
Fix# pom.xml: bump <version>2.25.4</version> for org.apache.logging.log4j:log4j-1.2-api
Maven/org.apache.logging.log4j:log4j-1.2-api
Introduced in: 3.0.0-beta1

No fixed version published yet for org.apache.logging.log4j:log4j-1.2-api (maven). Pin to a known-safe version or switch to an alternative.

References