Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4703 Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Github GHSA Github GHSA GHSA-p76j-5v6v-6c22 Apache NiFi JMS Deserialization issue
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-16T23:15:51.628Z

Reserved: 2017-12-07T00:00:00

Link: CVE-2018-1310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-23T14:29:00.450

Modified: 2024-11-21T03:59:35.923

Link: CVE-2018-1310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses