CVE-2018-1285 Apache log4net XML External Entity Vulnerability
**********************************
EDIT1: 2024/05/06
DESPITE THE "SOLVED" MARKINGS THE VULNERABILITY REMAINS. DO NOT BE FOOLED BY GOTO!
**********************************
Why is this ancient CVE from 2020 still present in latest (v2.2.28) GoToConnect Active Directory Connector software https://support.goto.com/connect/help/install-active-directory-connector-v2 ?
C:\Program Files\Logmein\Active Directory Connector\log4net.DLL
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1285
https://nvd.nist.gov/vuln/detail/CVE-2018-1285
https://www.fortiguard.com/encyclopedia/endpoint-vuln/2705
I opened a ticket with support and they closed it because the developers "are working on it" 4 years later.... Is GoTo taking security seriously?
Hi HZO-GB, welcome to the community.
The team is aware of this issue and it is being worked on currently. When an update is available I will share it here.