-
Notifications
You must be signed in to change notification settings - Fork 61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
log4net.dll Security Vulnerability #660
Comments
Critical Security Vulnerability in log4net.dll (CVE-2018-1285)Issue DetailsI've identified a critical security vulnerability in the Google Cloud SDK installation:
This vulnerability in log4net allows attackers to execute arbitrary code via a crafted serialized object in the data stream. Given its critical severity and high exploitability score, this poses a significant security risk. Steps to Reproduce
Expected BehaviorThe SDK should include the patched version of log4net.dll (2.0.10 or later) to mitigate this vulnerability. Actual BehaviorThe SDK includes an outdated and vulnerable version of log4net.dll (2.0.7.0). ImpactThis vulnerability could potentially allow malicious actors to execute arbitrary code, compromising the security of systems using the Google Cloud SDK. Proposed Solution
This issue requires urgent attention due to its severity. Could you please provide an update on when we can expect a fix for this vulnerability? Thank you for your prompt attention to this critical security matter. |
After nearly 2 years, this is still open. If the library is not used for anything, why to include it? If it is used for something why not upgrade to a non-vulnerable version? |
Fortinet FortiClient Vulnerability Scan reported the files:
C:\Program Files (x86)\Google\Cloud SDK\google-cloud-sdk\platform\PowerShell\GoogleCloud\1.0.1.10\fullclr\log4net.dll
C:\Program Files (x86)\Google\Cloud SDK\google-cloud-sdk\platform\PowerShell\GoogleCloudBeta\1.0.1.10\fullclr\log4net.dll
Contain Security Vulnerability CVE-2018-1285 for log4net.
How to upgrade log4net to 2.0.10 or higher?
Thanks in advance :-)
The text was updated successfully, but these errors were encountered: