CVE-2019-10080
published 2019-11-19CVE-2019-10080: The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
2.26%
80.9th percentile
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.3.0 – 1.9.2 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_apache6.5LOW
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: EAI (Jersey) — CVE-2019-10080
vendor_oracle·2021-04-15·CVSS 6.5
CVE-2019-10080 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: EAI (Jersey) — CVE-2019-10080
Oracle Oracle Siebel CRM Risk Matrix: EAI (Jersey) vulnerability
CVE: CVE-2019-10080
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Apache
Apache nifi: CVE-2019-10080
vendor_apache·CVSS 6.5
CVE-2019-10080 [LOW] Apache nifi: CVE-2019-10080
Apache nifi: CVE-2019-10080
Title: Potential Information Disclosure through XML External Entity Resolution in File Lookup Service Published: 2019-11-04 Severity: Low Products: Apache NiFi Affected Versions: 1.3.0 to 1.9.2 Fixed Versions: 1.10.0 Reporter: RunningSnail References CVE Record: CVE-2019-10080 NVD Record: CVE-2019-10080 Apache Jira Issue: NIFI-6301 GitHub Pull Request: 3507 The XMLFileLookupService allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services using XML External Entity resolution and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses. NiFi 1.10.0 adds a validator to ensure the XML file is not malicious. Users running a prior release sh
OSV
Apache NiFi information disclosure by XXE
osv·2019-12-02
CVE-2019-10080 [MEDIUM] Apache NiFi information disclosure by XXE
Apache NiFi information disclosure by XXE
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.
GHSA
Apache NiFi information disclosure by XXE
ghsa·2019-12-02
CVE-2019-10080 [MEDIUM] CWE-611 Apache NiFi information disclosure by XXE
Apache NiFi information disclosure by XXE
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2019-10080https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2019-10080https://www.oracle.com/security-alerts/cpuApr2021.html
2019-11-19
Published