← Back to CVE List

CVE-2018-1309

Published: 2018-05-23T14:29Z
Last Modified: 2024-11-21T03:59Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt