org.apache.nifi:nifi-hikari-dbcp-service
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.nifi:nifi-hikari-dbcp-servicepage 1 of 1
- CVE-2023-34468HIGHCVSS 8.8EG 8.8✓ Fixed in 1.22.02023-06-12
vulnerable: 1.16.0 ... 1.21.0 (10 versions)
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The re…
- CVE-2023-36542HIGHCVSS 8.8EG 8.8✓ Fixed in 1.23.02023-07-29
vulnerable: 1.16.0 ... 1.22.0 (11 versions)
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code executi…
Check whether org.apache.nifi:nifi-hikari-dbcp-service is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.nifi:nifi-hikari-dbcp-service CVEs against the assets you own.
Start Free Scan →