CRITICAL🇵🇱 Wersja polska

CVE-2017-15697

CVSS 9.8v3.0pub. 2018-01-23upd. 2024-11-21

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Nifi

    APP
    Apache
    1.0.0 – 1.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-1309CRITICAL9.8PL ✓same product

Apache NiFi: XXE w procesorze SplitXML umożliwia RCE lub ujawnienie danych

CVE-2017-5636CRITICAL9.8PL ✓same product

Apache NiFi — injection przez deserializację łańcucha proxy w klastrze

CVE-2026-62354HIGH7.7PL ✓same product

Apache NiFi: nieautoryzowana walidacja Parameter Context przez użytkownika read-only

CVE-2026-68981HIGH8.8PL ✓same product

Apache NiFi: atak typu zip bomb przez gzip-encoded HTTP request

CVE-2026-44914HIGH7.5same product

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extensio...