2/9/2023
3/9/2023
27/9/2024
CVE-2023-41180: Apache NiFi MiNiFi C++: Incorrect Certificate Validation in InvokeHTTP for MiNiFi C++
First published: Sat Sep 02 2023(Updated: )
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, disabling verification by default, when using HTTPS.
Mitigation: Set the Disable Peer Verification property of InvokeHTTP to true when using MiNiFi C++ versions 0.13.0 or 0.14.0. Upgrading to MiNiFi C++ 0.15.0 corrects the default behavior.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|
Apache Nifi Minifi C\+\+ | >=0.13.0<=0.14.0 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is CVE-2023-41180?
CVE-2023-41180 is a vulnerability in Apache NiFi MiNiFi C++ that allows an intermediary to present a forged certificate during TLS handshake negotiation.
Which versions of Apache NiFi MiNiFi C++ are affected by CVE-2023-41180?
Apache NiFi MiNiFi C++ versions 0.13 to 0.14 are affected by CVE-2023-41180.
How severe is CVE-2023-41180?
CVE-2023-41180 has a severity rating of medium.
What is the Common Weakness Enumeration (CWE) identifier for CVE-2023-41180?
The CWE identifier for CVE-2023-41180 is CWE-295.
How can I fix CVE-2023-41180?
To fix CVE-2023-41180, upgrade to a version of Apache NiFi MiNiFi C++ that is not affected by the vulnerability.
- collector/oss-sec
- alias/CVE-2023-41180
- collector/nvd-api
- collector/nvd-index
- agent/author
- agent/type
- agent/softwarecombine
- agent/first-publish-date
- agent/weakness
- agent/references
- agent/severity
- agent/title
- agent/description
- collector/mitre-cve
- source/MITRE
- agent/tags
- agent/last-modified-date
- agent/event
- agent/source
- agent/trending
- vendor/apache
- canonical/apache nifi minifi c\+\+
- version/apache nifi minifi c\+\+/0.13.0
- version/apache nifi minifi c\+\+/0.14.0
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203