CVE-2023-34468

CVE-2023-34468: Apache NiFi: Potential Code Injection with Database Services using H2

Vendor Apache Software Foundation
Product Apache NiFi
Weakness CWE-94 · Code injection
Published June 12, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

Key dates

Disclosure timeline

June 12, 2023 CVE published
February 13, 2025 Record updated