Back

MEDIUM

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack

Published Oct 10, 2017

Description

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Oct 10, 2017
Updated Sep 16, 2024
Reserved Aug 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-QJ7F-J6H9-G5RQ