Lucene search

K
osvGoogleOSV:GHSA-RQ96-QHC5-VM4R
HistoryJan 05, 2022 - 5:33 p.m.

Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi

2022-01-0517:33:32
Google
osv.dev
6

0.0005 Low

EPSS

Percentile

17.4%

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.

0.0005 Low

EPSS

Percentile

17.4%

Related for OSV:GHSA-RQ96-QHC5-VM4R