CVE-2023-34468
published 2023-06-12CVE-2023-34468: The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to…
PriorityP278high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
63.63%
99.1th percentile
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.
The resolution validates the Database URL and rejects H2 JDBC locations.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | >= 0.0.2 < 1.22.0 | 1.22.0 |
| apache_software_foundation | apache_nifi | 0.0.2 – 1.21.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/apache_nifi_h2_rce.rb↗
- →Monitor NiFi DBCPConnectionPool and HikariCPConnectionPool Controller Service configurations for Database URLs containing the H2 JDBC driver string (e.g., 'jdbc:h2:'). ↗
- →Alert on any NiFi API calls (authenticated) that set or update a Controller Service Database URL property containing H2 JDBC locations, as the fix specifically rejects these. ↗
- →Exploitation produces multiple reverse shells (5–7); monitor for unexpected child processes spawned from the NiFi JVM process, particularly on Linux hosts running NiFi 1.17.0–1.21.0. ↗
- ·The vulnerability requires an authenticated and authorized user; exploitation is not unauthenticated. Detections should still cover insider-threat and compromised-credential scenarios. ↗
- ·Upgrading to NiFi 1.22.0 disables H2 JDBC URLs in the default configuration; verify the default configuration has not been overridden post-upgrade. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_apache8.8
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2023-34468
vendor_apache·CVSS 8.8
CVE-2023-34468 Apache nifi: CVE-2023-34468
Apache nifi: CVE-2023-34468
Title: Potential Code Injection with Database Services using H2 Published: 2023-06-12 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.2 to 1.21.0 Fixed Versions: 1.22.0 Reporter: Matei 'Mal' Badanoiu References CVE Record: CVE-2023-34468 NVD Record: CVE-2023-34468 Apache Jira Issue: NIFI-11653 GitHub Pull Request: 7349 The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. Upgrading to NiFi 1.22.0 disables H2 JDBC URLs in the default configuration.
Severity: moderate
Affected versions: 1.21.0
OSV
Apache NiFi vulnerable to Code Injection
osv·2023-06-12
CVE-2023-34468 [HIGH] Apache NiFi vulnerable to Code Injection
Apache NiFi vulnerable to Code Injection
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.
The resolution validates the Database URL and rejects H2 JDBC locations.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
GHSA
Apache NiFi vulnerable to Code Injection
ghsa·2023-06-12
CVE-2023-34468 [HIGH] CWE-94 Apache NiFi vulnerable to Code Injection
Apache NiFi vulnerable to Code Injection
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.
The resolution validates the Database URL and rejects H2 JDBC locations.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/174398/Apache-NiFi-H2-Connection-String-Remote-Code-Execution.htmlhttp://www.openwall.com/lists/oss-security/2023/06/12/3https://lists.apache.org/thread/7b82l4f5blmpkfcynf3y6z4x1vqo59h8https://nifi.apache.org/security.html#CVE-2023-34468https://www.cyfirma.com/outofband/apache-nifi-cve-2023-34468-rce-vulnerability-analysis-and-exploitation/http://packetstormsecurity.com/files/174398/Apache-NiFi-H2-Connection-String-Remote-Code-Execution.htmlhttp://www.openwall.com/lists/oss-security/2023/06/12/3https://lists.apache.org/thread/7b82l4f5blmpkfcynf3y6z4x1vqo59h8https://nifi.apache.org/security.html#CVE-2023-34468https://www.cyfirma.com/outofband/apache-nifi-cve-2023-34468-rce-vulnerability-analysis-and-exploitation/
2023-06-12
Published