QID 981497
QID 981497: Dotnet (nuget) Security Update for log4net (GHSA-2cwj-8chv-9pp9)
Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2cwj-8chv-9pp9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2cwj-8chv-9pp9 -
github.com/advisories/GHSA-2cwj-8chv-9pp9
CVEs related to QID 981497
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2cwj-8chv-9pp9 | log4net |
|