Security Advisory

CVE-2020-13940

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-10-01 19:55:16
Last updated 2024-08-04 12:32:14
Assigner apache
CVSS score not scored
State PUBLISHED

Description

In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).