PT-2026-107236 · Apache · Log4Net
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache log4net versions 1.2.12 through 3.4.x
Description
Improper encoding or escaping of output occurs in the
RemoteSyslogAppender. Characters outside visible ASCII and space are removed from the record instead of being escaped, causing non-ASCII text and control characters, such as tabs, to disappear. This allows an attacker to manipulate data within a log message to make distinct values appear identical, such as using a zero-width space in a username to mimic an admin account. Only applications utilizing the RemoteSyslogAppender are affected.Recommendations
Upgrade to version 3.5.0.
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Log4Net