AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-22832

HIGH · CVSS 7.5 EPSS 1.41%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-02-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-22832
Severity
HIGH
CVSS
7.5
EPSS
1.41%
Apache

Original NVD Description

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.