CVE-2017-15703
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack.
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
- CVSS 3.0
- 5.0 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.86% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/nifi
- Source
- security@apache.org
References
- https://nifi.apache.org/security.html#CVE-2017-15703Vendor Advisory
- https://nifi.apache.org/security.html#CVE-2017-15703Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.