PT-2023-4686 · Apache · Apache Nifi

Mal

+1

·

Published

2023-08-18

·

Updated

2025-09-12

·

CVE-2023-40037

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.21.0 through 1.23.0
Description The issue is related to insufficient comparison in the Apache NiFi data processing platform. An authenticated and authorized user can bypass connection URL validation using custom input formatting, potentially allowing a remote attacker to gain unauthorized access to protected information. The vulnerability affects several Processors and Controller Services that support JDBC and JNDI JMS access.
Recommendations For Apache NiFi versions 1.21.0 through 1.23.0, upgrade to Apache NiFi 1.23.1 to enhance connection URL validation and introduce validation for additional related properties.

Exploit

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

BDU:2023-05103
BIT-NIFI-2023-40037
CVE-2023-40037
GHSA-23QF-3JF9-H3Q9

Affected Products

Apache Nifi