QID 730398
Date Published: 2022-03-15
QID 730398: Apache NiFi Information Disclosure By Extensible Markup Language (XML) External Entity (XXE) Vulnerability
Apache NiFi is a framework to support highly scalable and flexible dataflows. It can be run on laptops up through clusters of enterprise-class servers. Instead of dictating a particular dataflow or behavior, it empowers you to design your own optimal dataflow tailored to your specific environment.
CVE-2020-13940: Apache NiFi information disclosure by XXE.
Affected Versions:
Apache NiFi 1.0.0 - 1.11.4
QID Detection Logic:(Unauthenticated)
The QID sends a request to nifi-api/flow/about to check the vulnerable version of Apache NiFi.
Successful exploitation of the vulnerability can cause the disclosure of sensitive information.
Solution
The vendor has release patch, please check CVE-2020-13940
Vendor References
- CVE-2020-13940 -
nifi.apache.org/security#CVE-2020-13940
CVEs related to QID 730398
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Nifi |
|