Impact
The EventLogAppender in Apache log4net limits an event record to a fixed size. When the combined lengths of the log message and its metadata exceed the Windows Event Log limit, the entire record is silently discarded, leaving no trace. This loss of audit evidence can impede incident detection and forensic investigations. An attacker who can influence log content can construct a long message that causes the event to be omitted, effectively erasing their activity from the event log.
Affected Systems
Any application on Windows that uses Apache log4net with the EventLogAppender between versions 1.2.9 and just before 3.5.0 is affected. Non‑Windows platforms or other log4net appenders are not impacted.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an application that accepts untrusted input and logs it using EventLogAppender; the attacker can craft a large log entry to suppress evidence. While the flaw does not provide direct code execution, the ability to hide logs increases the risk of undetected malicious activity.
OpenCVE Enrichment