Impact
The RemoteSyslogAppender of Apache log4net fails to escape or encode characters outside the visible ASCII range and spaces; any such characters—including non‑ASCII symbols and control characters—are silently deleted from the log entry. As a result, log data intended to carry unique identifiers may appear indistinguishable, allowing an attacker to conceal a distinct value such as a user name containing a zero‑width space. This flaw does not provide code execution but can compromise the integrity and reliability of audit trails.
Affected Systems
Apache Software Foundation’s log4net library, specifically versions 1.2.12 through the pre‑3.5.0 series, is affected. Only deployments that employ the RemoteSyslogAppender are vulnerable; applications using other appenders are not impacted.
Risk and Exploitability
The vulnerability has a medium CVSS score of 5.3 and no EPSS data is available. It is not listed in CISA KEV. Because the flaw resides in a logging component that processes application data, an attacker who can influence log output, such as through user‑supplied input, could exploit the defect. The likely attack vector is local or remote application injection where the attacker causes the app to log crafted content. The risk is moderate; however, the potential impact on audit integrity warrants prompt remediation.
OpenCVE Enrichment