CVE-2017-12623
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
10/10/2017
Last modified:
20/04/2025
Description
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:nifi:1.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:nifi:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:nifi:1.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:nifi:1.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:nifi:1.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:nifi:1.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:nifi:1.3.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



