PT-2018-11592 · Apache · Apache Nifi

Åç Ç¬

·

Published

2018-05-23

·

Updated

2022-05-14

·

CVE-2018-1309

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NiFi versions prior to 1.6.0
Description The issue concerns an External XML Entity problem in the SplitXML processor, which could lead to information disclosure or remote code execution if malicious XML content is used.
Recommendations For versions prior to 1.6.0, upgrade to Apache NiFi 1.6.0 or a later version to apply the fix that disables external general entity parsing and disallows doctype declarations.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1309
GHSA-42WX-65G4-5CXV

Affected Products

Apache Nifi