[MAVEN:GHSA-Q4XF-3PMQ-3HW8] Improper Restriction of XML External Entity Reference in Apache NiFi

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).

Package Affected Version
pkg:maven/org.apache.nifi/nifi >= 1.0.0, <= 1.11.4
Package Fixed Version
pkg:maven/org.apache.nifi/nifi = 1.12.0-RC1
ID
MAVEN:GHSA-Q4XF-3PMQ-3HW8
Severity
moderate
URL
https://github.com/advisories/GHSA-q4xf-3pmq-3hw8
Published
2022-01-06T20:41:00
(2 years ago)
Modified
2023-02-01T05:05:15
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.nifi/nifi org.apache.nifi nifi >= 1.0.0 <= 1.11.4
Fixed pkg:maven/org.apache.nifi/nifi org.apache.nifi nifi = 1.12.0-RC1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...