CVE-2023-49145
published 2023-11-27CVE-2023-49145: Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.21%
64.9th percentile
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary
JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | >= 0.7.0 < 1.24.0 | 1.24.0 |
| apache_software_foundation | apache_nifi | 0.7.0 – 1.23.2 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_apache7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2023-49145
vendor_apache·CVSS 7.9
CVE-2023-49145 [HIGH] Apache nifi: CVE-2023-49145
Apache nifi: CVE-2023-49145
Title: Improper Neutralization of Input in Advanced User Interface for Jolt Published: 2023-11-27 Severity: High Products: Apache NiFi Affected Versions: 0.7.0 to 1.23.2 Fixed Versions: 1.24.0 Reporter: Dr. Oliver Matula, DB Systel GmbH References CVE Record: CVE-2023-49145 NVD Record: CVE-2023-49145 Apache Jira Issue: NIFI-12403 GitHub Pull Request: 8060 Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache
GHSA
Improper Neutralization of Input in Advanced User Interface for Jolt
ghsa·2023-11-28
CVE-2023-49145 [HIGH] CWE-79 Improper Neutralization of Input in Advanced User Interface for Jolt
Improper Neutralization of Input in Advanced User Interface for Jolt
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
OSV
Improper Neutralization of Input in Advanced User Interface for Jolt
osv·2023-11-28
CVE-2023-49145 [HIGH] Improper Neutralization of Input in Advanced User Interface for Jolt
Improper Neutralization of Input in Advanced User Interface for Jolt
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/11/27/5https://lists.apache.org/thread/j8rd0qsvgoj0khqck5f49jfbp0fm8r1ohttps://nifi.apache.org/security.html#CVE-2023-49145http://www.openwall.com/lists/oss-security/2023/11/27/5https://lists.apache.org/thread/j8rd0qsvgoj0khqck5f49jfbp0fm8r1ohttps://nifi.apache.org/security.html#CVE-2023-49145
2023-11-27
Published