Описание
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references.
Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references.
The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.
Ссылки
- Mailing ListVendor Advisory
- Vendor Advisory
- Mailing ListVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.2.0 (включая) до 1.19.1 (включая)
cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00243
Низкий
7.5 High
CVSS3
Дефекты
CWE-611
CWE-611
Связанные уязвимости
EPSS
Процентиль: 47%
0.00243
Низкий
7.5 High
CVSS3
Дефекты
CWE-611
CWE-611