CVE-2023-22832
published 2023-02-10CVE-2023-22832: The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.41%
69.6th percentile
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references.
Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references.
The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.2.0 – 1.19.1 | — |
| apache_software_foundation | apache_nifi | 1.2.0 – 1.19.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2023-22832
vendor_apache·CVSS 7.5
CVE-2023-22832 Apache nifi: CVE-2023-22832
Apache nifi: CVE-2023-22832
Title: Improper Restriction of XML External Entity References in ExtractCCDAAttributes Published: 2023-02-09 Severity: Medium Products: Apache NiFi Affected Versions: 1.2.0 to 1.19.1 Fixed Versions: 1.20.0 Reporter: Yi Cai of Chaitin Tech References CVE Record: CVE-2023-22832 NVD Record: CVE-2023-22832 Apache Jira Issue: NIFI-11029 GitHub Pull Request: 6828 The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the
GHSA
XML External Entity Reference in Apache NiFi
ghsa·2023-02-10
CVE-2023-22832 [HIGH] CWE-611 XML External Entity Reference in Apache NiFi
XML External Entity Reference in Apache NiFi
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.
OSV
XML External Entity Reference in Apache NiFi
osv·2023-02-10
CVE-2023-22832 [HIGH] XML External Entity Reference in Apache NiFi
XML External Entity Reference in Apache NiFi
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-10
Published