CVE-2017-12623

EUVD-2022-4986
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
apachenifi
1.0.0
apachenifi
1.0.1
apachenifi
1.1.0
apachenifi
1.1.1
apachenifi
1.1.2
apachenifi
1.2.0
apachenifi
1.3.0
𝑥
= Vulnerable software versions