Apache log4net是美国阿帕奇(Apache)基金会的一款日志输出工具。 Apache Log4net 3.3.0之前版本存在安全漏洞,该漏洞源于XmlLayout和XmlLayoutSchemaLog4J未清理XML 1.0规范禁止的字符,可能导致日志记录丢失。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Log4net | 0 ~ 3.3.0 |
cpe:2.3:a:apache:log4net:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40023 | Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XM | |
| CVE-2026-34481 | Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point val | |
| CVE-2026-34480 | Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden c | |
| CVE-2026-34479 | Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescape | |
| CVE-2026-34478 | Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibil | |
| CVE-2026-34477 | Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowin | |
| CVE-2026-39304 | Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Inco |
No comments yet