CVE Vulnerabilities

CVE-2017-12623

Improper Restriction of XML External Entity Reference

Published: Oct 10, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Nifi Apache 1.0.0 (including) 1.0.0 (including)
Nifi Apache 1.0.1 (including) 1.0.1 (including)
Nifi Apache 1.1.0 (including) 1.1.0 (including)
Nifi Apache 1.1.1 (including) 1.1.1 (including)
Nifi Apache 1.1.2 (including) 1.1.2 (including)
Nifi Apache 1.2.0 (including) 1.2.0 (including)
Nifi Apache 1.3.0 (including) 1.3.0 (including)

Potential Mitigations

References