CVE-2020-13940: XEE
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13940?
CVE-2020-13940 is a vulnerability in Apache NiFi 1.0.0 to 1.11.4 that allows trusted administrators to inadvertently configure a potentially malicious XML file, which can make external calls to services via XXE.
How severe is CVE-2020-13940?
CVE-2020-13940 has a severity rating of 5.5 (medium).
Who is affected by CVE-2020-13940?
Users of Apache NiFi versions 1.0.0 to 1.11.4 are affected by CVE-2020-13940.
How can CVE-2020-13940 be fixed?
To fix CVE-2020-13940, upgrade Apache NiFi to a version higher than 1.11.4.
Where can I find more information about CVE-2020-13940?
Detailed information about CVE-2020-13940 can be found on the Apache NiFi website at https://nifi.apache.org/security#CVE-2020-13940.