CyberRota Analysis
AI-GeneratedThe EventLogAppender in Apache log4net versions prior to 3.5.0 is vulnerable on Windows systems due to insufficient logging, allowing long messages to truncate and suppress entire log records. This could lead to a loss of critical event data, making it difficult to track malicious activities or system errors. Organizations using log4net on Windows should prioritize upgrading to version 3.5.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)