CVE-2022-29265
published 2022-04-30CVE-2022-29265: Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.50%
82.9th percentile
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors attempt to resolve XML External Entity references when configured with default property values: - EvaluateXPath - EvaluateXQuery - ValidateXml Apache NiFi flow configurations that include these Processors are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations in the default configuration for these Processors, and disallows XML External Entity resolution in standard services.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 0.0.1 – 1.16.0 | — |
| apache_software_foundation | apache_nifi | 0.0.1 to 1.16.0 – 0.0.1 to 1.16.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Multiple components in Apache NiFi do not restrict XML External Entity references
ghsa·2022-05-01
CVE-2022-29265 [HIGH] CWE-611 Multiple components in Apache NiFi do not restrict XML External Entity references
Multiple components in Apache NiFi do not restrict XML External Entity references
Apache NiFi is a system to process and distribute data. Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors attempt to resolve XML External Entity references when configured with default property values:
- EvaluateXPath
- EvaluateXQuery
- ValidateXml
Apache NiFi flow configurations that include these Processors are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. NiFi 1.16.1 disables Document Type Declarations in the default
OSV
Multiple components in Apache NiFi do not restrict XML External Entity references
osv·2022-05-01
CVE-2022-29265 [HIGH] Multiple components in Apache NiFi do not restrict XML External Entity references
Multiple components in Apache NiFi do not restrict XML External Entity references
Apache NiFi is a system to process and distribute data. Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors attempt to resolve XML External Entity references when configured with default property values:
- EvaluateXPath
- EvaluateXQuery
- ValidateXml
Apache NiFi flow configurations that include these Processors are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. NiFi 1.16.1 disables Document Type Declarations in the default
Apache
Apache nifi: CVE-2022-29265
vendor_apache·CVSS 7.5
CVE-2022-29265 Apache nifi: CVE-2022-29265
Apache nifi: CVE-2022-29265
Title: Improper Restriction of XML External Entity References in Multiple Components Published: 2022-04-29 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.1 to 1.16.0 Fixed Versions: 1.16.1 Reporter: David Handermann at exceptionfactory.com References CVE Record: CVE-2022-29265 NVD Record: CVE-2022-29265 Apache Jira Issue: NIFI-9901 GitHub Pull Request: 5962 Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors attempt to resolve XML External Entity references when configured with default property values: EvaluateXPath, EvaluateXQue
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-30
Published