CVE-2020-13940: Apache Nifi
Medium severity, CVSS 5.5. EPSS: 1.9% chance of exploitation in the next 30 days.
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Affected products
- Apache Nifi: from 1.0.0, up to and including 1.11.4
Published 2020-10-01. Last modified 2026-06-17.