MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocol
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 4.0%
probabilidade de exploração
4.0%top 10% das CVEs
exploração observada
nãonenhuma fonte reporta
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0
Produtos afetados
Apache Software Foundation · Apache NiFi - MiNiFi C++