OSV 1.4.0 · github-reviewed · 修改于 2022-01-05 04:18
发布时间
2022-01-06 01:33
GitHub 审查时间
2022-01-05 04:18
NVD 发布时间
2021-12-17 17:15
源文件
advisories/github-reviewed/2022/01/GHSA-rq96-qhc5-vm4r/GHSA-rq96-qhc5-vm4r.json
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.