CVE-2023-34468
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
- Affected products
- Apache Nifi
- Apache Nifi
- < 1.22.0
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 63.6% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2023-06-12
CVE-2023-34468 at NVD
16 known exploits for CVE-2023-34468
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2023-34468
CVE-2023-34468
CVE-2023-34468-PoC
asf__nifi_CVE-2023-34468_1-21-00
CVE-2023-34468
CVE-2023-34468-POC
Exploit for Code Injection in Apache Nifi
Exploit for Code Injection in Apache Nifi
Exploit for Code Injection in Apache Nifi
Exploit for Code Injection in Apache Nifi
Apache NiFi 1.21.0 Remote Code Execution
Apache NiFi 1.17.0 Remote Code Execution
Apache NiFi 0.0.2 Remote Code Execution
Apache NiFi H2 Connection String Remote Code Execution Exploit
Apache NiFi H2 Connection String Remote Code Execution
Apache NiFi H2 Connection String Remote Code Execution