OSV 1.4.0 · github-reviewed · 修改于 2021-03-30 00:20
发布时间
2022-01-07 04:41
GitHub 审查时间
2021-03-30 00:20
NVD 发布时间
2020-10-02 04:15
源文件
advisories/github-reviewed/2022/01/GHSA-q4xf-3pmq-3hw8/GHSA-q4xf-3pmq-3hw8.json
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).