ZeroHour

CVE-2017-12623

CVSS 3.0
6.5 medium
EPSS
2%p79
Published
()
Modified
Description

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Vendors
apache
Products
nifi
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.