Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2017-15697

malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or…

Technology

Apache NiFi

CVSS Score

9.8 / 10.0

Affected Versions

>=1.0.0 <=1.4.0

Upstream Fix

See upstream advisory

Published

January 23, 2018

OSSeva Coverage

Fixed upstream

Description

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Is your Apache NiFi deployment affected?

If you're running >=1.0.0 <=1.4.0, you need this patch. Book a discovery call to get covered.