CVE-2023-22832: Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references.
Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references.
The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22832?
CVE-2023-22832 is a vulnerability in Apache NiFi 1.2.0 through 1.19.1 that allows malicious XML documents to exploit XML External Entity references in the ExtractCCDAAttributes Processor.
How severe is CVE-2023-22832?
CVE-2023-22832 has a severity rating of 7.5, which is considered high.
How does CVE-2023-22832 impact Apache NiFi?
CVE-2023-22832 impacts Apache NiFi by potentially allowing malicious XML documents to exploit XML External Entity references in the ExtractCCDAAttributes Processor, leading to potential security breaches.
How can I fix CVE-2023-22832 in Apache NiFi?
To fix CVE-2023-22832 in Apache NiFi, you should update your installation to a version that is not affected, specifically a version higher than 1.19.1.
Where can I find more information about CVE-2023-22832?
You can find more information about CVE-2023-22832 on the Apache NiFi security page and the Apache mailing list.