chocolatey / chocolatey-licensed-issues

Issues for Licensed Editions of Chocolatey
19 stars 13 forks source link

Chocolatey Extension - XML External Entity attack in log4net (CVE-2018-1285) #252

Closed sync-by-unito[bot] closed 3 years ago

sync-by-unito[bot] commented 3 years ago

Enhancement Information

We need to update to the latest log4net package version in all Chocolatey code bases, including this one. This is due to an:

XML External Entity attack in log4net

which can:

Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.

The recommendation is to update to at least 2.0.10, however, we have decided to go straight to 2.0.12.

References

┆Issue is synchronized with this Gitlab issue by Unito ┆Milestone: 2.2.0