GHSA-chxj-gxww-q98w

Suggest an improvement
Source
https://github.com/advisories/GHSA-chxj-gxww-q98w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-chxj-gxww-q98w/GHSA-chxj-gxww-q98w.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-chxj-gxww-q98w
Aliases
Downstream
Published
2026-06-22T09:30:45Z
Modified
2026-09-14T18:55:27Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:L/U:Clear CVSS Calculator
Summary
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Details

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.

Database specific
{
    "cwe_ids": [
        "CWE-116"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-14T18:14:05Z",
    "nvd_published_at": "2026-06-22T08:17:05Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.apache.nifi:nifi-cdc-mysql-processors

Package

Name
org.apache.nifi:nifi-cdc-mysql-processors
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-cdc-mysql-processors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2.0
Fixed
2.10.0

Affected versions

1.*
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.18.0
1.19.0
1.19.1
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.23.2
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
2.*
2.0.0-M1
2.0.0-M2
2.0.0-M3
2.0.0-M4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.0
2.9.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-chxj-gxww-q98w/GHSA-chxj-gxww-q98w.json"