← voltar
CVE-2023-34468highCWE-94

Apache NiFi: Potential Code Injection with Database Services using H2

48Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 8.8epss 64%
da publicação à arma0 dias
Publicada no NVD12 de jun.
metasploit12 de jun.
probabilidade de exploração
64%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H