CVE-2023-34468

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/06/2023
Last modified:
13/02/2025

Description

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.<br /> <br /> The resolution validates the Database URL and rejects H2 JDBC locations.<br /> <br /> You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* 0.0.2 (including) 1.22.0 (excluding)