CVE-2018-1309 is a vulnerability in Apache NiFi
Published on May 23, 2018
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Products Associated with CVE-2018-1309
Want to know whenever a new CVE is published for Apache NiFi? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache NiFi Version 0.1.0 - 1.5.0 is affected by CVE-2018-1309Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.