Severity: important

Affected versions:

- Apache NiFi 1.8.0 through 1.21.0

Description:

The JndiJmsConnectionFactoryProvider Controller Service, along with the 
ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow 
an authenticated and authorized user to configure URL and library properties 
that enable deserialization of untrusted data from a remote location.

The resolution validates the JNDI URL and restricts locations to a set of 
allowed schemes.

This issue is being tracked as NIFI-11614 

Credit:

Veraxy00 of Qianxin TI Center (finder)
Matei "Mal" Badanoiu (reporter)

References:

https://nifi.apache.org/security.html#CVE-2023-34212
https://nifi.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-34212
https://issues.apache.org/jira/browse/NIFI-11614

Timeline:

2023-05-28: reported
2023-05-29: confirmed
2023-06-01: resolved

Reply via email to