VulnerabilityModified
CVE-2021-44145
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
MEDIUM 6.5EPSS 1.70%
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/nifi
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2021/12/17/1Mailing List, Third Party Advisory
- https://nifi.apache.org/security.html#1.15.1-vulnerabilitiesVendor Advisory
- http://www.openwall.com/lists/oss-security/2021/12/17/1Mailing List, Third Party Advisory
- https://nifi.apache.org/security.html#1.15.1-vulnerabilitiesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.