cbcvebase.
CVE-2017-12632
published 2018-01-23

CVE-2017-12632: A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to…

PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.85%
85.1th percentile
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachenifi<= 1.4.0
apachenifi
apache_software_foundationapache_nifi
apache_software_foundationapache_nifi

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.