CVE-2021-33191 Information

Description

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an gent-update\ command which was designed to patch the application binary. This \patching\ command defaults to calling a trusted binary but might be modified to an arbitrary value through a ## CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.openwall.com/lists/oss-security/2021/08/24/1 http://www.openwall.com/lists/oss-security/2021/08/24/1 https://lists.apache.org/thread.html/r6f27a2454f5f67dbe4e21c8eb1db537b01863a0bc3758f28aa60f032@%3Cannounce.apache.org%3E

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: