CVE-2026-44913: falha de média gravidade em Apache NiFi
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.2epss 0.6%
probabilidade de exploração
0.6%top 51% das CVEs
exploração observada
nãonenhuma fonte reporta
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:L/U:Clear
Produtos afetados
Apache Software Foundation · Apache NiFiCVEs relacionadas — Apache NiFi
No mesmo produto, das mais perigosas para as menos.
CVE-2023-34468HIGHApache NiFi: Potential Code Injection with Database Services using H2EPSS 61.9%CVE-2024-37389MEDIUMApache NiFi: Improper Neutralization of Input in Parameter Context DescriptionEPSS 24.0%CVE-2017-15697—CVE-2017-15697EPSS 4.8%CVE-2018-1309—CVE-2018-1309EPSS 4.5%CVE-2020-1928—CVE-2020-1928EPSS 4.0%CVE-2022-33140—Improper Neutralization of Command Elements in Shell User Group ProviderEPSS 3.7%