apache nifi CVE-2018-1309 is a vulnerability in Apache NiFi
Published on May 23, 2018

Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

NVD


Products Associated with CVE-2018-1309

Want to know whenever a new CVE is published for Apache NiFi? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache NiFi Version 0.1.0 - 1.5.0 is affected by CVE-2018-1309

Exploit Probability

EPSS
3.67%
Percentile
87.71%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.