Description
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Remediation
References
https://nifi.apache.org/security.html#CVE-2017-12623
Related Vulnerabilities
CVE-2023-41900 Vulnerability in maven package org.eclipse.jetty:jetty-openid
CVE-2022-2053 Vulnerability in maven package io.undertow:undertow-core
CVE-2019-1003096 Vulnerability in maven package org.jenkins-ci.plugins:testfairy
CVE-2019-10401 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-1000398 Vulnerability in maven package org.jenkins-ci.main:jenkins-core