CVE-2021-33191 Information
Jun 07, 2022
cve
Description
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an gent-update\ command which was designed to patch the application binary. This \patching\ command defaults to calling a trusted binary but might be modified to an arbitrary value through a ## CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.openwall.com/lists/oss-security/2021/08/24/1 http://www.openwall.com/lists/oss-security/2021/08/24/1 https://lists.apache.org/thread.html/r6f27a2454f5f67dbe4e21c8eb1db537b01863a0bc3758f28aa60f032@%3Cannounce.apache.org%3E
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: