Apache Software Foundation Apache Nifi Minifi C vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_nifi_minifi_c.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-33191P2CRITICALCVSS 9.8≥ 0.5.0, < Apache NiFi - MiNiFi C++*2021-08-24
CVE-2021-33191 [CRITICAL] CWE-78 CVE-2021-33191: From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the app
nvd
CVE-2023-41180P4MEDIUMCVSS 5.9≥ 0.13.0, ≤ 0.14.02023-09-03
CVE-2023-41180 [MEDIUM] CWE-295 CVE-2023-41180: Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allow
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, disabling verification by default, when using HTTPS.
Mitigation: Set the Disable Peer Ver
nvd