Back to search
CVE-2023-34468
Published: Jun 12, 2023
Modified: Feb 13, 2025
PUBLISHED
Description
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache NiFi | affected 0.0.2 - <= 1.21.0 |
Weaknesses (CWE)
References
https://nifi.apache.org/security.html#CVE-2023-34468
release-notes
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now