CVE-2023-36542
Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources
描述
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recommended mitigation.
如何修補 CVE-2023-36542
要修補 CVE-2023-36542,請將受影響套件升級到下列已修補版本。
- —未列出修補版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
- —升級至 1.23.0 或更新版本
CVE-2023-36542 正在被利用嗎?
低 — EPSS 為 1.6%,目前沒有觀察到大規模利用活動。
受影響套件(9)
- >= 0.0.2, <= 1.22.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
- >= 0.0.2, < 1.23.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |