PT-2026-107235 · Apache · Log4Net
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache log4net versions 1.2.9 through 3.4.x
Description
Insufficient logging occurs in the
EventLogAppender on Windows. Long messages are truncated to a fixed size that, when combined with log and source names, exceeds the Windows Event Log capacity. This causes the event log to store and report nothing, allowing a party capable of influencing log message data to suppress the entire record by increasing its length.Recommendations
Upgrade to version 3.5.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Log4Net