CVE-2017-12623
published 2017-10-10CVE-2017-12623: An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to…
PriorityP336medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.94%
77.8th percentile
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_apache6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
XML External Entity Reference in Apache NiFi
osv·2022-05-17
CVE-2017-12623 [MEDIUM] XML External Entity Reference in Apache NiFi
XML External Entity Reference in Apache NiFi
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
GHSA
XML External Entity Reference in Apache NiFi
ghsa·2022-05-17
CVE-2017-12623 [MEDIUM] CWE-611 XML External Entity Reference in Apache NiFi
XML External Entity Reference in Apache NiFi
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Apache
Apache nifi: CVE-2017-12623
vendor_apache·CVSS 6.5
CVE-2017-12623 [HIGH] Apache nifi: CVE-2017-12623
Apache nifi: CVE-2017-12623
Title: Improper Restriction of XML External Entity References in Template Upload Resources Published: 2017-10-02 Severity: High Products: Apache NiFi Affected Versions: 1.0.0 to 1.3.0 Fixed Versions: 1.4.0 Reporter: Paweł Gocyla with further information from Mike Cole References CVE Record: CVE-2017-12623 NVD Record: CVE-2017-12623 Apache Jira Issue: NIFI-4353 GitHub Pull Request: 2128 Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. NiFi 1.14.0 properly handles XML External Entities. Users running a prior release should upgrade to 1.4.0.
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-10
Published