First published: Thu Oct 01 2020(Updated: )
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache NiFi | >=1.0.0<=1.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13940 is a vulnerability in Apache NiFi 1.0.0 to 1.11.4 that allows trusted administrators to inadvertently configure a potentially malicious XML file, which can make external calls to services via XXE.
CVE-2020-13940 has a severity rating of 5.5 (medium).
Users of Apache NiFi versions 1.0.0 to 1.11.4 are affected by CVE-2020-13940.
To fix CVE-2020-13940, upgrade Apache NiFi to a version higher than 1.11.4.
Detailed information about CVE-2020-13940 can be found on the Apache NiFi website at https://nifi.apache.org/security#CVE-2020-13940.