Description
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0671 | In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE). |
Github GHSA |
GHSA-q4xf-3pmq-3hw8 | Improper Restriction of XML External Entity Reference in Apache NiFi |
References
| Link | Providers |
|---|---|
| https://nifi.apache.org/security#CVE-2020-13940 |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T12:32:14.454Z
Reserved: 2020-06-08T00:00:00.000Z
Link: CVE-2020-13940
No data.
Status : Modified
Published: 2020-10-01T20:15:13.097
Modified: 2024-11-21T05:02:11.600
Link: CVE-2020-13940
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA