← Back to CVE List

CVE-2019-10080

Published: 2019-11-19T22:15Z
Last Modified: 2024-11-21T04:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt