QID 730552

Date Published: 2022-07-04

QID 730552: Apache NiFi Improper Restriction of Extensible Markup Language (XML) External Entity Vulnerability

Apache NiFi is a framework to support highly scalable and flexible dataflows. It can be run on laptops up through clusters of enterprise-class servers. Instead of dictating a particular dataflow or behavior, it empowers you to design your own optimal dataflow tailored to your specific environment.

CVE-2022-29265: Apache NiFi Improper Restriction of XML External Entity References in Multiple Components vulnerability.

Affected Versions:
Apache NiFi 0.0.1 - 1.16.0

QID Detection Logic:(Unauthenticated)
The QID sends a request to nifi-api/flow/about to check the vulnerable version of Apache NiFi.

Successful exploitation of the vulnerability can cause the disclosure of sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has release patch, please check CVE-2022-29265
    Vendor References

    CVEs related to QID 730552

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-29265 URL Logo nifi.apache.org/security.html#CVE-2022-29265