PT-2025-34481 · Apache+2 · Apache Log4Cxx+2

CVE-2025-54812

·

Publicado

2023-05-08

·

Atualizado

2025-11-05

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Log4cxx versions prior to 1.5.0
Description: Apache Log4cxx contains an Improper Output Neutralization for Logs issue. When using HTMLLayout, logger names are not properly escaped when writing to an HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could inject HTML or Javascript, potentially leading to cross-site scripting (XSS) when a user opens the generated HTML log file in their browser. This requires the following sequence: Log4cxx is configured to use HTMLLayout, the logger name comes from an untrusted string, a logger with the compromised name logs a message, and a user opens the generated HTML log file.
Recommendations: Upgrade to version 1.5.0.

Exploit

Correção

DoS

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-13810
BDU:2025-13811
BDU:2025-13812
CVE-2025-54812
DLA-4322-1
OPENSUSE-SU-2025:15549-1

Produtos afetados

Apache Log4Cxx
Debian
Red Os