org.apache.nifi:nifi-dbcp-base
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.nifi:nifi-dbcp-basepage 1 of 1
- CVE-2023-34468HIGHCVSS 8.8EG 8.8✓ Fixed in 1.22.02023-06-12
vulnerable: 1.19.0, 1.19.1, 1.20.0, 1.21.0
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The re…
- CVE-2023-40037MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.23.12023-08-18
vulnerable: 1.21.0, 1.22.0, 1.23.0
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and author…
Check whether org.apache.nifi:nifi-dbcp-base is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.nifi:nifi-dbcp-base CVEs against the assets you own.
Start Free Scan →