Medium severity6.1NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026
CVE-2020-1933
CVE-2020-1933
Description
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.nifi:nifiMaven | >= 1.0.0, < 1.11.0 | 1.11.0 |
Affected products
4- osv-coords2 versions
>= 1.0.0, <= 1.10.0+ 1 more
- (no CPE)range: >= 1.0.0, <= 1.10.0
- (no CPE)range: >= 1.0.0, < 1.11.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-pqhq-xx62-2v2pghsaADVISORY
- nifi.apache.org/security.htmlnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-1933ghsaADVISORY
- github.com/apache/nifi/pull/3991ghsaWEB
News mentions
0No linked articles in our index yet.