ZeroHour

CVE-2021-44145

CVSS 3.1
6.5 medium
EPSS
2%p76
Published
()
Modified
Description

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.

Vendors
apache
Products
nifi
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.