356
VMScore

CVE-2017-12623

Published: 10/10/2017 Updated: 05/11/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Vulnerable Product Search on Vulmon Subscribe to Product

apache nifi 1.1.2

apache nifi 1.2.0

apache nifi 1.3.0

apache nifi 1.0.0

apache nifi 1.0.1

apache nifi 1.1.1

apache nifi 1.1.0