CVE-2017-12623
Last modified
CVE-2017-12623 is a vulnerability of currently unknown severity. An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. EPSS estimates a 1.94% chance of exploitation in the next 30 days.
Description
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | 1.0.0 |
| Apache | Nifi | 1.0.1 |
| Apache | Nifi | 1.1.0 |
| Apache | Nifi | 1.1.1 |
| Apache | Nifi | 1.1.2 |
| Apache | Nifi | 1.2.0 |
| Apache | Nifi | 1.3.0 |
References
- https://nifi.apache.org/security.html#CVE-2017-12623Vendor Advisory
- https://nifi.apache.org/security.html#CVE-2017-12623Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12623?
How severe is CVE-2017-12623?
How do I fix CVE-2017-12623?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-12618Apache Portable Runtime Utility (APR-util) 1.6.0 and prior f…
- CVE-2017-12619Apache Zeppelin prior to 0.7.3 was vulnerable to session fix…
- CVE-2017-1262IBM Security Guardium 10.0 is vulnerable to HTTP response sp…
- CVE-2017-12620When loading models or dictionaries that contain XML it is p…
- CVE-2017-12621During Jelly (xml) file parsing with Apache Xerces, if a cus…9.8
- CVE-2017-12622When an Apache Geode cluster before v1.3.0 is operating in s…
- CVE-2017-12624Apache CXF supports sending and receiving attachments via ei…
- CVE-2017-12625Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.…
- CVE-2017-12626Apache POI in versions prior to release 3.17 are vulnerable …7.5
- CVE-2017-12627In Apache Xerces-C XML Parser library before 3.2.1, processi…
- CVE-2017-12628The JMX server embedded in Apache James, also used by the co…
- CVE-2017-12629Remote code execution occurs in Apache Solr before 7.1 with …9.8
Are you affected by CVE-2017-12623?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
