Lucene search

K
osvGoogleOSV:GHSA-Q4XF-3PMQ-3HW8
HistoryJan 06, 2022 - 8:41 p.m.

Improper Restriction of XML External Entity Reference in Apache NiFi

2022-01-0620:41:00
Google
osv.dev
8

0.0004 Low

EPSS

Percentile

12.7%

In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).

0.0004 Low

EPSS

Percentile

12.7%

Related for OSV:GHSA-Q4XF-3PMQ-3HW8