Логотип exploitDog
bind:CVE-2023-34212
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-34212

Количество 2

Количество 2

nvd логотип

CVE-2023-34212

больше 2 лет назад

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-65wh-g8x8-gm2h

больше 2 лет назад

Apache NiFi vulnerable to Deserialization of Untrusted Data

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-34212

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-65wh-g8x8-gm2h

Apache NiFi vulnerable to Deserialization of Untrusted Data

CVSS3: 6.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу