CVE-2021-44145
published 2021-12-17CVE-2021-44145: In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.70%
74.5th percentile
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | >= 0.1.0 < 1.15.1 | 1.15.1 |
| apache_software_foundation | apache_nifi | Apache NiFi – 1.15.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_apache6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi
osv·2022-01-05
CVE-2021-44145 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi
Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi
ghsa·2022-01-05
CVE-2021-44145 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi
Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
Apache
Apache nifi: CVE-2021-44145
vendor_apache·CVSS 6.5
CVE-2021-44145 [LOW] Apache nifi: CVE-2021-44145
Apache nifi: CVE-2021-44145
Title: Potential Information Disclosure through XML External Entity Resoltion in TransformXML Published: 2021-12-15 Severity: Low Products: Apache NiFi Affected Versions: 0.1.0 to 1.15.0 Fixed Versions: 1.15.1 Reporter: DangKhai at Viettel Cyber Security References CVE Record: CVE-2021-44145 NVD Record: CVE-2021-44145 Apache Jira Issue: NIFI-9399 GitHub Pull Request: 5542 In the TransformXML processor, an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information. The Secure processing property in TransformXML will now apply to the configured XSLT file as well as flow files being transformed. Users running any previous NiFi release should upgrade to 1.15.1.
Severity: low
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-17
Published