CVE-2018-1310

Severity
7.5HIGH
EPSS
1.8%
top 17.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 14

Description

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/nifi< 1.6.0
Mavenorg.apache.nifi:nifi< 1.6.0

🔴Vulnerability Details

3
GHSA
Apache NiFi JMS Deserialization issue2022-05-14
OSV
Apache NiFi JMS Deserialization issue2022-05-14
CVEList
CVE-2018-1310: Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability2018-05-23

💥Exploits & PoCs

1
Exploit-DB
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)2018-01-17

📋Vendor Advisories

1
Apache
Apache nifi: CVE-2018-1310