Vulnerabilities > CVE-2023-34212 - Deserialization of Untrusted Data vulnerability in Apache Nifi
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/06/12/2
- https://lists.apache.org/thread/w5rm46fxmvxy216tglf0dv83wo6gnzr5
- https://nifi.apache.org/security.html#CVE-2023-34212
- http://www.openwall.com/lists/oss-security/2023/06/12/2
- https://nifi.apache.org/security.html#CVE-2023-34212
- https://lists.apache.org/thread/w5rm46fxmvxy216tglf0dv83wo6gnzr5