GHSA-r969-8v3h-23v9
HIGHCVE-2023-36542Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The
- Affected
- >=0.0.2
- Fixed in
- 1.23.0
- Weakness
- CWE-94
- Published
- 2023-07-29
- Source
- github