High severity7.5NVD Advisory· Published Oct 1, 2020· Updated Jun 17, 2026
CVE-2020-9487
CVE-2020-9487
Description
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly request download tokens, preventing legitimate users from requesting download tokens.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.nifi:nifiMaven | >= 1.0.0, < 1.12.0-RC1 | 1.12.0-RC1 |
Affected products
4- Apache/NiFidescription
- osv-coords2 versions
>= 1.0.0, <= 1.11.4+ 1 more
- (no CPE)range: >= 1.0.0, <= 1.11.4
- (no CPE)range: >= 1.0.0, < 1.12.0-RC1
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-3pp3-77j6-8ph6ghsaADVISORY
- nifi.apache.org/securitynvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-9487ghsaADVISORY
- github.com/apache/nifi/commit/01e42dfb3291c3a3549023edadafd2d8023f3042ghsaWEB
News mentions
0No linked articles in our index yet.