Improper Output Neutralization for Logs vulnerability in Apache Log4cxx.
When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them.
This issue affects Apache Log4cxx: before 1.5.0.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Sat, 23 Aug 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache log4cxx |
|
Vendors & Products |
Apache
Apache log4cxx |
Fri, 22 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 22 Aug 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them. This issue affects Apache Log4cxx: before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue. | |
Title | Apache Log4cxx: Improper escaping with JSONLayout | |
Weaknesses | CWE-117 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: apache
Published: 2025-08-22T18:45:42.611Z
Updated: 2025-08-22T19:05:49.161Z
Reserved: 2025-07-30T01:20:34.786Z
Link: CVE-2025-54813

Updated: 2025-08-22T19:05:43.288Z

Status : Received
Published: 2025-08-22T19:15:40.003
Modified: 2025-08-22T19:15:40.003
Link: CVE-2025-54813

No data.