CVE-2021-44145

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
References
Configurations

Configuration 1

cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*

Information

Published : 2021-12-17 09:15

Updated : 2021-12-29 08:38


NVD link : CVE-2021-44145

Mitre link : CVE-2021-44145

Products Affected
No products.
CWE