maven package report

Is org.apache.nifi:nifi-cdc-mysql-bundle safe?

1 known vulnerability, worst severity HIGH.

cvss
8.8

how bad it is if exploited, out of 10

epss
1.9%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-r969-8v3h-23v9, the advisory selected below

// advisories

GHSA-r969-8v3h-23v9

HIGHCVE-2023-36542

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The

Affected
>=0.0.2
Fixed in
1.23.0
Weakness
CWE-94
Published
2023-07-29
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 03:35 UTC. The most recent advisory here was published 2023-07-29. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.apache.nifi:nifi-cdc-mysql-bundle safe? maven package security report | CyberXYZ