QID 730384
Date Published: 2022-03-14
QID 730384: Apache NiFi Checkstyle Dependency Extensible Markup Language (XML) External Entity (XXE) Vulnerability
Apache NiFi is a framework to support highly scalable and flexible dataflows. It can be run on laptops up through clusters of enterprise-class servers. Instead of dictating a particular dataflow or behavior, it empowers you to design your own optimal dataflow tailored to your specific environment.
CVE-2019-9658 - The com.puppycrawl.tools:checkstyle dependency had a XXE vulnerability.
Affected Versions:
Apache NiFi 1.8.0 - 1.11.4
QID Detction Logic:(Unauthenticated)
The QID sends a request to nifi-api/flow/about to check the vulnerable version of Apache NiFi.
Successful exploitation of the vulnerability can cause the disclosure of sensitive information.
Solution
The vendor has release patch, please check CVE-2019-9658
Vendor References
- CVE-2019-9658 -
nifi.apache.org/security#CVE-2019-9658
CVEs related to QID 730384
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Nifi |
|