Логотип exploitDog
bind:CVE-2023-36542
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-36542

Количество 3

Количество 3

nvd логотип

CVE-2023-36542

больше 2 лет назад

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recommended mitigation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-r969-8v3h-23v9

больше 2 лет назад

Apache NiFi Code Injection vulnerability

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-06376

больше 2 лет назад

Уязвимость компонента Remote Resource Handler платформы обработки данных Apache NiFi, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-36542

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recommended mitigation.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-r969-8v3h-23v9

Apache NiFi Code Injection vulnerability

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-06376

Уязвимость компонента Remote Resource Handler платформы обработки данных Apache NiFi, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу