CVE-2023-34468

Source
https://cve.org/CVERecord?id=CVE-2023-34468
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34468.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-34468
Aliases
Published
2023-06-12T16:15:10.130Z
Modified
2026-04-10T04:58:32.622187Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.

The resolution validates the Database URL and rejects H2 JDBC locations.

You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

References

Affected packages

Git / github.com/apache/nifi

Affected ranges

Type
GIT
Repo
https://github.com/apache/nifi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0.0.2"
        },
        {
            "fixed": "1.22.0"
        }
    ]
}

Affected versions

docker/nifi-1.*
docker/nifi-1.2.0
nifi-0.*
nifi-0.2.0-incubating-RC1
nifi-0.4.1
nifi-0.4.1-RC1
nifi-0.6.0
nifi-0.6.0-RC2
nifi-1.*
nifi-1.1.0-RC2
nifi-1.2.0-RC2
nifi-1.20.0-RC1
rel/nifi-1.*
rel/nifi-1.1.0
rel/nifi-1.2.0
rel/nifi-1.20.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34468.json"