Denial of service via deserialization attack in nifi
Moderate severity
GitHub Reviewed
Published
Oct 25, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 1.5.0
Patched versions
1.5.0
Description
Reviewed
Oct 25, 2019
Published to the GitHub Advisory Database
Oct 25, 2019
Last updated
Jan 9, 2023
A vulnerability found in Apache NIFI before 1.5.0-RC1. Attacker can perform XXE attacks through JAXB.
References