We found results for “”
CVE-2023-34468
Good to know:
Date: June 12, 2023
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
Language: Java
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Code Injection
CWE-94Top Fix
Upgrade Version
Upgrade to version org.apache.nifi:nifi-dbcp-service:1.22.0, org.apache.nifi:nifi-hikari-dbcp-service:1.22.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |