PT-2023-24742 · Apache · Apache Nifi

Mal

+2

·

Published

2023-06-12

·

Updated

2025-09-12

·

CVE-2023-34212

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.8.0 through 1.21.0
Description The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes.
Recommendations Upgrade to version 1.22.0 or later, which fixes this issue.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BIT-NIFI-2023-34212
CVE-2023-34212
GHSA-65WH-G8X8-GM2H

Affected Products

Apache Nifi