Apache NiFi: Potential Code Injection with Database Services using H2
CVE-2023-34468
Key Information:
- Vendor
- Apache
- Status
- Vendor
- CVE Published:
- 12 June 2023
Badges
Summary
The DBCPConnectionPool and HikariCPConnectionPool services in Apache NiFi versions 0.0.2 through 1.21.0 are susceptible to a vulnerability that allows an authenticated and authorized user to configure a Database URL leveraging the H2 driver, leading to potential execution of custom code. The recommended resolution involves validating the Database URL and rejecting H2 JDBC locations to mitigate this risk. Users are advised to upgrade to version 1.22.0 or later to address this issue effectively.
Affected Version(s)
Apache NiFi 0.0.2 <= 1.21.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
Get notified when SecurityVulnerability.io launches alerting π
Well keep you posted π§
News Articles
References
EPSS Score
72% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
- π°
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved