Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5265
HistoryOct 11, 2017 - 7:44 a.m.

XML External Entities (XXE) Attacks

2017-10-1107:44:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.0005 Low

EPSS

Percentile

17.3%

apache-nifi is vulnerable to XML External Entities (XXE) attacks. The library does not properly handle XML template files, allowing a malicious user to inject external entities that can lead to sensitive information being displayed.

CPENameOperatorVersion
nifi-framework-corele1.3.0

0.0005 Low

EPSS

Percentile

17.3%

Related for VERACODE:5265