Description
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Remediation
References
https://nifi.apache.org/security.html#CVE-2017-12632
Related Vulnerabilities
CVE-2021-23264 Vulnerability in maven package org.craftercms:crafter-search
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-syntax-html5
CVE-2018-1000862 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2015-5174 Vulnerability in maven package org.apache.tomcat:catalina