CVE-2023-22832: Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes

2023-02-10 Thread David Handermann
Severity: moderate Description: The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type

[ANNOUNCE] Apache NiFi 1.20.0 release.

2023-02-10 Thread Joe Witt
Hello The Apache NiFi team would like to announce the release of Apache NiFi 1.20.0. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. Apache NiFi was made for dataflow. It supports highly configurable directed graphs of data routing, transformation,