PT-2023-4686 · Apache · Apache Nifi
Mal
+1
·
Published
2023-08-18
·
Updated
2025-09-12
·
CVE-2023-40037
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 1.21.0 through 1.23.0
Description
The issue is related to insufficient comparison in the Apache NiFi data processing platform. An authenticated and authorized user can bypass connection URL validation using custom input formatting, potentially allowing a remote attacker to gain unauthorized access to protected information. The vulnerability affects several Processors and Controller Services that support JDBC and JNDI JMS access.
Recommendations
For Apache NiFi versions 1.21.0 through 1.23.0, upgrade to Apache NiFi 1.23.1 to enhance connection URL validation and introduce validation for additional related properties.
Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Nifi