Medium severity6.5NVD Advisory· Published Nov 19, 2019· Updated Jun 17, 2026
CVE-2019-10080
CVE-2019-10080
Description
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.nifi:nifi-securityMaven | >= 1.3.0, < 1.10.0 | 1.10.0 |
org.apache.nifi:nifiMaven | >= 1.3.0, < 1.10.0 | 1.10.0 |
Affected products
4- NiFi/NiFidescription
- ghsa-coords2 versions
>= 1.3.0, < 1.10.0+ 1 more
- (no CPE)range: >= 1.3.0, < 1.10.0
- (no CPE)range: >= 1.3.0, < 1.10.0
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-744r-vv2g-2x6gghsaADVISORY
- nifi.apache.org/security.htmlnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10080ghsaADVISORY
- github.com/apache/nifi/pull/3507ghsaWEB
- lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3EghsaWEB
- www.oracle.com/security-alerts/cpuApr2021.htmlnvdWEB
- lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Envd
News mentions
0No linked articles in our index yet.