OS Command Injection in Apache NiFi Registry and Apache Nifi - CVE-2022-33140

 

OS Command Injection in Apache NiFi Registry and Apache Nifi - CVE-2022-33140

Published: June 15, 2022


Vulnerability identifier: #VU64418
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33140
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in ShellUserGroupProvider implementation. A remote authenticated user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.



Affected software

Apache NiFi Registry
Apache Nifi

How to mitigate CVE-2022-33140

Install updates from vendor's website.

Apache NiFi Registry - update to 1.16.3
Apache Nifi - update to 1.16.3

External References

Related Security Bulletins