Apache NiFi API Remote Code Execution
Posted by deepcore on November 29, 2020 – 10:55 pm
This Metasploit module uses the NiFi API to create an ExecuteProcess processor that will execute OS commands. The API must be unsecured (or credentials provided) and the ExecuteProcess processor must be available. An ExecuteProcessor processor is created then is configured with the payload and started. The processor is then stopped and deleted.
Post a reply
You must be logged in to post a comment.