Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yi Cai

#37471of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2023-18714
7.5
2023-02-10
Apache · Apache Nifi · CVE-2023-22832
**Name of the Vulnerable Software and Affected Versions** Apache NiFi versions 1.2.0 through 1.19.1 **Description** The ExtractCCDAAttributes Processor in Apache NiFi does not restrict XML External Entity references, making flow configurations that include this processor vulnerable to malicious XML documents containing Document Type Declarations with XML External Entity references. **Recommendations** For Apache NiFi versions 1.2.0 through 1.19.1, the resolution involves disabling Document Type Declarations and disallowing XML External Entity resolution in the ExtractCCDAAttributes Processor.