A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1953 A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Github GHSA Github GHSA GHSA-29ph-fjf3-c5cm Apache NiFi XSS issue in context path handling
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-17T03:48:44.883Z

Reserved: 2017-10-21T00:00:00

Link: CVE-2017-15697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-23T22:29:00.337

Modified: 2024-11-21T03:15:01.477

Link: CVE-2017-15697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses