Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Veraxy00

#43572of 56,330
6.5Total CVSS
Vulnerabilities · 1
PT-2023-24742
6.5
2023-06-12
Apache · Apache Nifi · CVE-2023-34212
**Name of the Vulnerable Software and Affected Versions** Apache NiFi versions 1.8.0 through 1.21.0 **Description** The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. **Recommendations** Upgrade to version 1.22.0 or later, which fixes this issue.