CVE-2018-1310
CVE-2018-1310 is a high-severity vulnerability in Apache Nifi with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-502.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 3% (87th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-502
- Affected product: Apache Nifi
- Published:
- Last modified:
Description
Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Frequently asked questions
- What is CVE-2018-1310?
- Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
- How severe is CVE-2018-1310?
- CVE-2018-1310 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2018-1310 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (87th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-1310?
- CVE-2018-1310 affects Apache Nifi. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-1310?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2018-1310 published?
- CVE-2018-1310 was published on 2018-05-23 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Nifi
- CVE-2026-68979 — Critical (CVSS 9.8): Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce…
- CVE-2018-1309 — Critical (CVSS 9.8): Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure…
- CVE-2017-15697 — Critical (CVSS 9.8): A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause…
- CVE-2017-5636 — Critical (CVSS 9.8): In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain…
- CVE-2026-68980 — Critical (CVSS 9.1): Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts…
- CVE-2026-39816 — High (CVSS 8.8): The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code…
All CVEs affecting Apache Nifi →
Other CWE-502 (Deserialization of Untrusted Data) vulnerabilities
- CVE-2026-69836 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release…
- CVE-2026-11756 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…
- CVE-2026-41104 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose…
- CVE-2026-43633 — Critical (CVSS 10.0): HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a…
- CVE-2026-33819 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Browse all CWE-502 (Deserialization of Untrusted Data) vulnerabilities →