Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| log4net(NuGet) | 0 | 2.0.10 | N/A |
CVSS Metrics