← voltar
CVE-2023-36542highexploração observadaCWE-94

Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources

43Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Actcvss 8.8epss 1.9%
da publicação à arma
Publicada no NVD29 de jul.
VulnCheck+417d
probabilidade de exploração
1.9%top 21% das CVEs
exploração observada
simVulnCheck
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recommended mitigation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H