Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Yi Cai

#38226de 56,337
7.5CVSS total
Vulnerabilidades · 1
PT-2023-18714
7.5
2023-02-10
Apache · Apache Nifi · CVE-2023-22832
**Name of the Vulnerable Software and Affected Versions** Apache NiFi versions 1.2.0 through 1.19.1 **Description** The ExtractCCDAAttributes Processor in Apache NiFi does not restrict XML External Entity references, making flow configurations that include this processor vulnerable to malicious XML documents containing Document Type Declarations with XML External Entity references. **Recommendations** For Apache NiFi versions 1.2.0 through 1.19.1, the resolution involves disabling Document Type Declarations and disallowing XML External Entity resolution in the ExtractCCDAAttributes Processor.