Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hxjp-q6c3-38fx

Опубликовано: 10 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

XML External Entity Reference in Apache NiFi

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.

Пакеты

Наименование

org.apache.nifi:nifi-ccda-processors

maven
Затронутые версииВерсия исправления

>= 1.2.0, < 1.20.0

1.20.0

EPSS

Процентиль: 47%
0.00243
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.

EPSS

Процентиль: 47%
0.00243
Низкий

7.5 High

CVSS3

Дефекты

CWE-611