Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yi Cai

#36399de 53,634
7.5CVSS total
Vulnerabilidades · 1
PT-2023-18714
7.5
2023-02-10
Apache · Apache Nifi · CVE-2023-22832
**Name of the Vulnerable Software and Affected Versions** Apache NiFi versions 1.2.0 through 1.19.1 **Description** The ExtractCCDAAttributes Processor in Apache NiFi does not restrict XML External Entity references, making flow configurations that include this processor vulnerable to malicious XML documents containing Document Type Declarations with XML External Entity references. **Recommendations** For Apache NiFi versions 1.2.0 through 1.19.1, the resolution involves disabling Document Type Declarations and disallowing XML External Entity resolution in the ExtractCCDAAttributes Processor.