Description
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Remediation
References
https://nifi.apache.org/security.html#CVE-2017-12623
Related Vulnerabilities
CVE-2013-1966 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2023-27096 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2015-7501 Vulnerability in maven package org.apache.commons:commons-collections4
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-undertow
CVE-2018-1999026 Vulnerability in maven package de.tracetronic.jenkins.plugins:ecutest