PT-2026-51283 · Apache · Apache Nifi
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 1.2.0 through 2.9.0
Description
Improper escaping of database table names in the CaptureChangeMySQL Processor allows for the injection of SQL commands through crafted naming. This issue affects installations utilizing the CaptureChangeMySQL Processor.
Recommendations
Update to version 2.10.0.
As a temporary mitigation, restrict or disable the use of the CaptureChangeMySQL Processor.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi