[ANNOUNCE] Apache NiFi 1.23.2 Released

2023-08-23 Thread David Handermann
The Apache NiFi Team is pleased to announce the release of Apache NiFi 1.23.2. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. https://nifi.apache.org The release artifacts can be downloaded from the project website.

CVE-2023-40037: Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs

2023-08-19 Thread David Handermann
Severity: moderate Affected versions: - Apache NiFi 1.21.0 through 1.23.0 Description: Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted

[ANNOUNCE] Apache NiFi 1.23.1 Released

2023-08-19 Thread David Handermann
The Apache NiFi team is pleased to announce the release of Apache NiFi 1.23.1. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. Apache NiFi was made for dataflow. It supports highly configurable directed graphs of data routing, transformation, and

CVE-2022-29265: Apache NiFi: Improper Restriction of XML External Entity References in Multiple Components

2022-04-29 Thread David Handermann
Processor Property in EvaluateXPath and EvaluateXQuery mitigates the vulnerability for those Processors. No mitigation is available for the ValidateXml Processor or the Standard Content Viewer. Credit: David Handermann at exceptionfactory.com reported this issue. References: https

CVE-2023-22832: Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes

2023-02-10 Thread David Handermann
Severity: moderate Description: The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type

CVE-2023-34468: Apache NiFi: Potential Code Injection with Database Services using H2

2023-06-12 Thread David Handermann
Severity: important Affected versions: - Apache NiFi 0.0.2 through 1.21.0 Description: The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that

CVE-2023-34212: Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components

2023-06-12 Thread David Handermann
Severity: important Affected versions: - Apache NiFi 1.8.0 through 1.21.0 Description: The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL

CVE-2023-36542: Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources

2023-07-29 Thread David Handermann
Severity: moderate Affected versions: - Apache NiFi 0.0.2 through 1.22.0 Description: Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location

CVE-2023-49145: Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt

2023-11-28 Thread David Handermann
Affected versions: - Apache NiFi 0.7.0 through 1.23.2 Description: Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is

[ANNOUNCE] Apache NiFi 2.0.0-M1 Released

2023-11-27 Thread David Handermann
The Apache NiFi Team is pleased to announce the release of Apache NiFi 2.0.0-M1. Version 2.0.0-M1 is the initial milestone release version of Apache NiFi 2.0.0. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. https://nifi.apache.org The release

[ANNOUNCE] Apache NiFi 2.0.0-M2 Released

2024-01-29 Thread David Handermann
The Apache NiFi Team is pleased to announce the release of Apache NiFi 2.0.0-M2. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. https://nifi.apache.org The release artifacts can be downloaded from the project website.

[ANNOUNCE] Apache NiFi 2.0.0-M3 Released

2024-05-17 Thread David Handermann
The Apache NiFi Team is pleased to announce the release of Apache NiFi 2.0.0-M3. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. https://nifi.apache.org The release artifacts can be downloaded from the project website.