4
CVSSv2

CVE-2019-10080

Published: 19/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache nifi

Mailing Lists

[CVEID]:CVE-2019-10080 [PRODUCT]:Apache NiFi [VERSION]:Apache NiFi 130 to 192 [PROBLEMTYPE]:Information Disclosure [REFERENCES]:nifiapacheorg/securityhtml#CVE-2019-10080 [DESCRIPTION]:As reported by RunningSnail, the XMLFileLookupService in NiFi versions 130 to 192 allowed trusted users to inadvertently configure a potential ...