CVE-2023-49145
Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt
7.9
HIGH
CVSS 3.1
EPSS 1.2%
Description
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0 is the recommended mitigation.
How to fix CVE-2023-49145
To remediate CVE-2023-49145, upgrade the affected package to a fixed version below.
- —upgrade to 1.24.0 or later
- —upgrade to 1.24.0 or later
Is CVE-2023-49145 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 0.7.0, < 1.24.0
- from 0, < 1.24.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.9 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L |