{"id":"GHSA-xwx6-vmj4-5rv8","summary":"Denial of service via deserialization attack in nifi","details":"A vulnerability found in Apache NIFI before 1.5.0-RC1. Attacker can perform XXE attacks through JAXB.","aliases":["CVE-2017-15703"],"modified":"2023-11-08T03:58:58.180714Z","published":"2019-10-25T19:42:50Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-10-25T17:13:19Z","nvd_published_at":null,"cwe_ids":["CWE-502"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/apache/nifi/commit/9e2c7be7d3c6a380c5f61074d9a5a690b617c3dc"}],"affected":[{"package":{"name":"org.apache.nifi:nifi-framework-cluster-protocol","ecosystem":"Maven","purl":"pkg:maven/org.apache.nifi/nifi-framework-cluster-protocol"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0"}]}],"versions":["0.0.1-incubating","0.0.2-incubating","0.1.0-incubating","0.2.0-incubating","0.2.1","0.3.0","0.4.0","0.4.1","0.5.0","0.5.1","0.6.0","0.6.1","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","1.0.0","1.0.0-BETA","1.0.1","1.1.0","1.1.1","1.1.2","1.2.0","1.3.0","1.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-xwx6-vmj4-5rv8/GHSA-xwx6-vmj4-5rv8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"}]}