← Back

CVE-2017-12623

nvd nist
Published: Oct 10, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Affected (7)

Products: Apache: Nifi
1 product
Nifi
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 1.0.0
Version 1.0.1
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.2.0
Version 1.3.0

References (2)

Source: security@apache.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.