GHSA-23qf-3jf9-h3q9

Suggest an improvement
Source
https://github.com/advisories/GHSA-23qf-3jf9-h3q9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-23qf-3jf9-h3q9/GHSA-23qf-3jf9-h3q9.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-23qf-3jf9-h3q9
Aliases
Published
2023-08-19T00:30:29Z
Modified
2023-11-08T05:23:45.974938Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Apache NiFi Insufficient Property Validation vulnerability
Details

Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.

Database specific
{
    "nvd_published_at": "2023-08-18T22:15:10Z",
    "cwe_ids": [
        "CWE-184",
        "CWE-697"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-08-21T20:16:05Z"
}
References

Affected packages

Maven / org.apache.nifi:nifi-dbcp-base

Package

Name
org.apache.nifi:nifi-dbcp-base
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-dbcp-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.21.0
Fixed
1.23.1

Affected versions

1.*

1.21.0
1.22.0
1.23.0

Maven / org.apache.nifi:nifi-jms-processors

Package

Name
org.apache.nifi:nifi-jms-processors
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-jms-processors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.21.0
Fixed
1.23.1

Affected versions

1.*

1.21.0
1.22.0
1.23.0

Maven / org.apache.nifi:nifi-dbcp-service-api

Package

Name
org.apache.nifi:nifi-dbcp-service-api
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-dbcp-service-api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.21.0
Fixed
1.23.1

Affected versions

1.*

1.21.0
1.22.0
1.23.0

Maven / org.apache.nifi:nifi-dbcp-service-bundle

Package

Name
org.apache.nifi:nifi-dbcp-service-bundle
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-dbcp-service-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.21.0
Fixed
1.23.1

Affected versions

1.*

1.21.0
1.22.0
1.23.0