← Back to CVE List

CVE-2020-13940

Published: 2020-10-01T20:15Z
Last Modified: 2024-11-21T05:02Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt