Vulnerability Description
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 1.3.0, <= 1.9.2 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b
- https://nifi.apache.org/security.html#CVE-2019-10080Vendor Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b
- https://nifi.apache.org/security.html#CVE-2019-10080Vendor Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html
FAQ
What is CVE-2019-10080?
CVE-2019-10080 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to servi...
How severe is CVE-2019-10080?
CVE-2019-10080 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10080?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nifi.