Apache NiFi: Potential Code Injection with Database Services using H2
Vulnerability Description
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-34468
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Matei "Mal" Badanoiu
References
- https://nifi.apache.org/security.html#CVE-2023-34468
- https://lists.apache.org/thread/7b82l4f5blmpkfcynf3y6z4x1vqo59h8
- http://www.openwall.com/lists/oss-security/2023/06/12/3
- http://packetstormsecurity.com/files/174398/Apache-NiFi-H2-Connection-String-Remote-Code-Execution.html
- https://www.cyfirma.com/outofband/apache-nifi-cve-2023-34468-rce-vulnerability-analysis-and-exploitation/
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →