Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Paweł Gocyla

#40727de 53,638
6.5CVSS total
Vulnerabilidades · 1
PT-2017-12607
6.5
2017-10-10
Apache · Apache Nifi · CVE-2017-12623
**Name of the Vulnerable Software and Affected Versions** Apache NiFi versions prior to 1.4.0 **Description** The issue allows an authorized user to upload a template containing malicious code, which can then access sensitive files via an XML External Entity (XXE) attack. This occurs due to improper handling of XML External Entities. **Recommendations** For Apache NiFi versions prior to 1.4.0, upgrade to Apache NiFi 1.4.0 or a later version to properly handle XML External Entities and prevent XXE attacks.