CVE-2023-34212: Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location.
The resolution validates the JNDI URL and restricts locations to a set of allowed schemes.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.nifi:nifi-jms-processorsto a version that resolves this vulnerability.Fixed in 1.22.0 - Upgrade
Upgrade
Apache NiFito a version that resolves this vulnerability.Fixed in 1.22.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34212?
The severity of CVE-2023-34212 is medium with a severity value of 6.5.
How does CVE-2023-34212 affect Apache NiFi?
CVE-2023-34212 affects Apache NiFi versions 1.8.0 through 1.21.0.
What is the vulnerability in CVE-2023-34212?
The vulnerability in CVE-2023-34212 allows an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location.
How can I fix CVE-2023-34212?
To fix CVE-2023-34212, upgrade Apache NiFi to a version beyond 1.21.0.
Where can I find more information about CVE-2023-34212?
More information about CVE-2023-34212 can be found at the following references: - [http://www.openwall.com/lists/oss-security/2023/06/12/2](http://www.openwall.com/lists/oss-security/2023/06/12/2) - [https://lists.apache.org/thread/w5rm46fxmvxy216tglf0dv83wo6gnzr5](https://lists.apache.org/thread/w5rm46fxmvxy216tglf0dv83wo6gnzr5) - [https://nifi.apache.org/security.html#CVE-2023-34212](https://nifi.apache.org/security.html#CVE-2023-34212)