← Back to browse · API

CVE-2023-34468

Severity
HIGH
CVSS
8.8
EPSS
0.63633
Risk score
57.47
CISA KEV
No
PoC
No
Published
2023-06-12
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-1917, GHSA-XM2M-2Q6H-22JW
Products
Apache Software Foundation:Apache NiFi 0.0.2 ≤1.21.0
Sources
euvd EUVD-2023-1917

Description

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

References