← back
CVE-2021-44145

Apache NiFi information disclosure by XXE

EPSS 1.7%
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →