
=====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN422
_____________________________________________________________________

DATE                : 25/08/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache NiFi MiNiFi C++ versions
                                   prior to 0.10.0.

=====================================================================
http://mail-archives.apache.org/mod_mbox/www-announce/202108.mbox/%3cb40026c0-b109-3d2c-09f3-7fdbb1438d23@apache.org%3e
_____________________________________________________________________

CVE-2021-33191: Apache NiFi - MiNiFi C++: MiNiFi CPP arbitrary script
execution is possible on the agent's host machine through the c2
protocol


Description:

>From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an
"agent-update" command which was designed to patch the application
binary.

This "patching" command defaults to calling a trusted binary, but might
be modified to an arbitrary value through a "c2-update" command. Said
command is then executed using the same privileges as the application
binary.

 This was addressed in version 0.10.0

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================




