In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
| Software | From | Fixed in |
|---|---|---|
| apache / nifi | 0.1.0 | 1.15.1 |
org.apache.nifi / nifi
|
- | 1.15.1 |