Description
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
Remediation
References
https://nifi.apache.org/security.html#1.15.1-vulnerabilities
http://www.openwall.com/lists/oss-security/2021/12/17/1
Related Vulnerabilities
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elasticsearch
CVE-2013-2165 Vulnerability in maven package org.richfaces:richfaces
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2023-25767 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials
CVE-2022-34195 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector