QID 730398

Date Published: 2022-03-15

QID 730398: Apache NiFi Information Disclosure By Extensible Markup Language (XML) External Entity (XXE) Vulnerability

Apache NiFi is a framework to support highly scalable and flexible dataflows. It can be run on laptops up through clusters of enterprise-class servers. Instead of dictating a particular dataflow or behavior, it empowers you to design your own optimal dataflow tailored to your specific environment.

CVE-2020-13940: Apache NiFi information disclosure by XXE.

Affected Versions:
Apache NiFi 1.0.0 - 1.11.4

QID Detection Logic:(Unauthenticated)
The QID sends a request to nifi-api/flow/about to check the vulnerable version of Apache NiFi.

Successful exploitation of the vulnerability can cause the disclosure of sensitive information.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has release patch, please check CVE-2020-13940
    Vendor References

    CVEs related to QID 730398

    Software Advisories
    Advisory ID Software Component Link
    Apache Nifi URL Logo nifi.apache.org/security#CVE-2020-13940