In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://nifi.apache.org/security.html#1.15.1-vulnerabilities | vendor advisory |
http://www.openwall.com/lists/oss-security/2021/12/17/1 | third party advisory mailing list |