Loading HuntDB...

GHSA-h5f6-7m57-f2rg

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0

Related CVEs

Key Information

GHSA ID
GHSA-h5f6-7m57-f2rg
Published
May 24, 2022 7:12 PM
Last Modified
May 24, 2022 7:12 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.