CVE-2023-34468 is a critical vulnerability affecting Apache NiFi versions 0.0.2 through 1.21.0, allowing authenticated users to achieve remote code execution by manipulating H2 database connection URLs within DBCPConnectionPool and HikariCPConnectionPool Controller Services. With a CVSS score of 8.8 (High), it presents a low-complexity network attack vector that can lead to complete compromise of confidentiality, integrity, and availability. While not yet on the KEV catalog, a Metasploit module exists, and the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation. Organizations are strongly advised to upgrade to NiFi version 1.22.0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.0.2, < 1.22.0CPE matchmatch criteria | cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* | ||
>= 0.0.2, <= 1.21.0CPE match | cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.