Vulnerability Description
Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | < 1.6.0 |
Related Weaknesses (CWE)
References
- https://nifi.apache.org/security.html#CVE-2018-1310Vendor Advisory
- https://nifi.apache.org/security.html#CVE-2018-1310Vendor Advisory
FAQ
What is CVE-2018-1310?
CVE-2018-1310 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The f...
How severe is CVE-2018-1310?
CVE-2018-1310 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1310?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nifi.