Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.nifi/nifi-dbcp-service-bundle
  4. ›
  5. CVE-2023-40037

CVE-2023-40037: Apache NiFi Insufficient Property Validation vulnerability

August 19, 2023 (updated February 13, 2025)

Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.

References

  • github.com/advisories/GHSA-23qf-3jf9-h3q9
  • github.com/apache/nifi
  • github.com/apache/nifi/commit/064550aacc189f39d7ddd2c0446068adf250f1bf
  • github.com/apache/nifi/pull/7586
  • issues.apache.org/jira/browse/NIFI-11920
  • lists.apache.org/thread/bqbjlrs2p5ghh8sbk5nsxb8xpf9l687q
  • nifi.apache.org/security.html
  • nvd.nist.gov/vuln/detail/CVE-2023-40037

Code Behaviors & Features

Detect and mitigate CVE-2023-40037 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.21.0 before 1.23.1

Fixed versions

  • 1.23.1

Solution

Upgrade to version 1.23.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-184: Incomplete List of Disallowed Inputs
  • CWE-697: Incorrect Comparison

Source file

maven/org.apache.nifi/nifi-dbcp-service-bundle/CVE-2023-40037.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 25 Oct 2025 12:18:21 +0000.