VYPR

CaptureChangeMySQL Processor

by Apache

CVEs (1)

  • CVE-2026-44913HigJun 22, 2026
    risk 0.47cvss 7.2epss 0.00

    Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection…