CVE-2018-1309
CVE-2018-1309
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 4.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 May 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Affected products
Apache Software Foundation · Apache NiFiWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →