CVE-2018-1310: High severity apache nifi vulnerability
Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-1310.
What is the severity of CVE-2018-1310?
The severity of CVE-2018-1310 is high with a score of 7.5.
What is the affected software version of CVE-2018-1310?
The affected software version of CVE-2018-1310 is Apache NiFi 1.6.0.
How can I fix CVE-2018-1310?
To fix CVE-2018-1310, you need to upgrade the activemq-client library to version 5.15.3 or a higher version.
Where can I find more information about CVE-2018-1310?
You can find more information about CVE-2018-1310 at the following reference: https://nifi.apache.org/security.html#CVE-2018-1310.