PT-2017-12607 · Apache · Apache Nifi

Mike Cole

+1

·

Publicado

2017-10-10

·

Atualizado

2022-05-17

·

CVE-2017-12623

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions prior to 1.4.0
Description The issue allows an authorized user to upload a template containing malicious code, which can then access sensitive files via an XML External Entity (XXE) attack. This occurs due to improper handling of XML External Entities.
Recommendations For Apache NiFi versions prior to 1.4.0, upgrade to Apache NiFi 1.4.0 or a later version to properly handle XML External Entities and prevent XXE attacks.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12623
GHSA-QJ7F-J6H9-G5RQ

Produtos afetados

Apache Nifi