PT-2019-4251 · Apache+1 · Apache Nifi+2
Published
2019-11-04
·
Updated
2021-06-14
·
CVE-2019-10080
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 1.3.0 through 1.9.2
Description
The issue is related to the XMLFileLookupService component, which can be configured by trusted users to use a potentially malicious XML file. This XML file can make external calls to services via XXE, potentially revealing sensitive information such as the versions of Java, Jersey, and Apache used by the NiFi instance. The vulnerability is associated with incorrect restriction of XML links to external objects, allowing a remote attacker to gain unauthorized access to protected information using a specially crafted XML file.
Recommendations
For Apache NiFi versions 1.3.0 through 1.9.2, consider restricting access to the XMLFileLookupService component until a patch is available. As a temporary workaround, avoid using the XMLFileLookupService with untrusted XML files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi
Java
Jersey