OS Command Injection in Apache NiFi Registry and Apache Nifi - CVE-2022-33140
Published: June 15, 2022
Vulnerability identifier: #VU64418
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33140
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in ShellUserGroupProvider implementation. A remote authenticated user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Affected software
Apache NiFi Registry
Apache Nifi
Apache Nifi
How to mitigate CVE-2022-33140
Install updates from vendor's website.
Apache NiFi Registry - update to 1.16.3
Apache Nifi - update to 1.16.3
Apache Nifi - update to 1.16.3