Apache NiFi vulnerable to Code Injection
High severity
GitHub Reviewed
Published
Jun 12, 2023
to the GitHub Advisory Database
•
Updated Apr 12, 2024
Description
Published by the National Vulnerability Database
Jun 12, 2023
Published to the GitHub Advisory Database
Jun 12, 2023
Reviewed
Jun 12, 2023
Last updated
Apr 12, 2024
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.
The resolution validates the Database URL and rejects H2 JDBC locations.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
References