PT-2018-11592 · Apache · Apache Nifi

Åç Ç¬

·

Publicado

2018-05-23

·

Atualizado

2022-05-14

·

CVE-2018-1309

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NiFi versions prior to 1.6.0
Description The issue concerns an External XML Entity problem in the SplitXML processor, which could lead to information disclosure or remote code execution if malicious XML content is used.
Recommendations For versions prior to 1.6.0, upgrade to Apache NiFi 1.6.0 or a later version to apply the fix that disables external general entity parsing and disallows doctype declarations.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1309
GHSA-42WX-65G4-5CXV

Produtos afetados

Apache Nifi