Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for…
apache·CWE-611·Published 2020-05-11