CVE-2019-10080
Apache NiFi information disclosure by XXE
6.5
MEDIUM
CVSS 3.1
EPSS 2.3%
描述
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.
如何修補 CVE-2019-10080
要修補 CVE-2019-10080,請將受影響套件升級到下列已修補版本。
- —升級至 1.10.0 或更新版本
- —升級至 1.10.0 或更新版本
CVE-2019-10080 正在被利用嗎?
低 — EPSS 為 2.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 1.3.0, < 1.10.0
- >= 1.3.0, < 1.10.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |