PT-2019-4251 · Apache+1 · Apache Nifi+2

Published

2019-11-04

·

Updated

2021-06-14

·

CVE-2019-10080

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.3.0 through 1.9.2
Description The issue is related to the XMLFileLookupService component, which can be configured by trusted users to use a potentially malicious XML file. This XML file can make external calls to services via XXE, potentially revealing sensitive information such as the versions of Java, Jersey, and Apache used by the NiFi instance. The vulnerability is associated with incorrect restriction of XML links to external objects, allowing a remote attacker to gain unauthorized access to protected information using a specially crafted XML file.
Recommendations For Apache NiFi versions 1.3.0 through 1.9.2, consider restricting access to the XMLFileLookupService component until a patch is available. As a temporary workaround, avoid using the XMLFileLookupService with untrusted XML files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04852
CVE-2019-10080
GHSA-744R-VV2G-2X6G

Affected Products

Apache Nifi
Java
Jersey