PT-2017-12607 · Apache · Apache Nifi
Mike Cole
+1
·
Publicado
2017-10-10
·
Atualizado
2022-05-17
·
CVE-2017-12623
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions prior to 1.4.0
Description
The issue allows an authorized user to upload a template containing malicious code, which can then access sensitive files via an XML External Entity (XXE) attack. This occurs due to improper handling of XML External Entities.
Recommendations
For Apache NiFi versions prior to 1.4.0, upgrade to Apache NiFi 1.4.0 or a later version to properly handle XML External Entities and prevent XXE attacks.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Nifi