Bitnami package
nifi
pkg:bitnami/nifi
Vulnerabilities (37)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-87976 | Hig | 8.1 | >= 0.4.0, < 2.12.0 | 2.12.0 | Sep 16, 2026 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components withou | |
| CVE-2026-86089 | Hig | 7.1 | >= 2.11.0, < 2.12.0 | 2.12.0 | Sep 16, 2026 | Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without e | |
| CVE-2026-82561 | Med | 6.5 | >= 1.5.0, < 2.12.0 | 2.12.0 | Sep 16, 2026 | Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for th | |
| CVE-2026-81866 | Med | 4.3 | >= 2.9.0, < 2.12.0 | 2.12.0 | Sep 16, 2026 | Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration step can apply Asset an | |
| CVE-2026-70469 | Hig | 7.5 | >= 2.11.0, < 2.12.0 | 2.12.0 | Sep 16, 2026 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Enco | |
| CVE-2026-68981 | Hig | 7.5 | >= 1.5.0, < 2.11.0 | 2.11.0 | Aug 3, 2026 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client t | |
| CVE-2026-68980 | Cri | 9.1 | >= 2.0.0, < 2.11.0 | 2.11.0 | Aug 3, 2026 | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifi | |
| CVE-2026-68979 | Cri | 9.8 | >= 1.10.0, < 2.11.0 | 2.11.0 | Aug 3, 2026 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework | |
| CVE-2026-62354 | Med | 4.3 | >= 1.10.0, < 2.11.0 | 2.11.0 | Aug 3, 2026 | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined comp | |
| CVE-2026-54665 | Med | 5.3 | >= 0.0.1, < 2.10.0 | 2.10.0 | Jun 22, 2026 | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict va | |
| CVE-2026-44914 | Hig | 7.2 | >= 1.12.0, < 2.10.0 | 2.10.0 | Jun 22, 2026 | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework auth | |
| CVE-2026-44913 | Hig | 7.2 | >= 1.2.0, < 2.10.0 | 2.10.0 | Jun 22, 2026 | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection option | |
| CVE-2026-44911 | Med | 6.3 | >= 1.15.0, < 2.10.0 | 2.10.0 | Jun 22, 2026 | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to inv | |
| CVE-2026-39816 | Hig | 8.8 | >= 2.0.0, < 2.9.0 | 2.9.0 | May 8, 2026 | The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, e | |
| CVE-2026-25903 | Med | 6.6 | >= 1.1.0, < 2.8.0 | 2.8.0 | Feb 17, 2026 | Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annot | |
| CVE-2025-66524 | Hig | 8.8 | >= 1.20.0, < 2.7.0 | 2.7.0 | Dec 19, 2025 | Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserial | |
| CVE-2024-56512 | Med | 5.4 | >= 1.10.0, < 2.1.0 | 2.1.0 | Dec 28, 2024 | Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context, | |
| CVE-2024-45477 | Med | 4.6 | >= 1.10.0, < 1.28.0 | 1.28.0 | Oct 29, 2024 | Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary Java | |
| CVE-2023-49145 | Hig | 7.9 | >= 0.7.0, < 1.24.0 | 1.24.0 | Nov 27, 2023 | Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a | |
| CVE-2023-40037 | Med | 6.5 | >= 1.21.0, < 1.23.1 | 1.23.1 | Aug 18, 2023 | Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL valid |
- affected >= 0.4.0, < 2.12.0fixed 2.12.0
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components withou
- affected >= 2.11.0, < 2.12.0fixed 2.12.0
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without e
- affected >= 1.5.0, < 2.12.0fixed 2.12.0
Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for th
- affected >= 2.9.0, < 2.12.0fixed 2.12.0
Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration step can apply Asset an
- affected >= 2.11.0, < 2.12.0fixed 2.12.0
Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Enco
- affected >= 1.5.0, < 2.11.0fixed 2.11.0
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client t
- affected >= 2.0.0, < 2.11.0fixed 2.11.0
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifi
- affected >= 1.10.0, < 2.11.0fixed 2.11.0
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework
- affected >= 1.10.0, < 2.11.0fixed 2.11.0
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined comp
- affected >= 0.0.1, < 2.10.0fixed 2.10.0
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict va
- affected >= 1.12.0, < 2.10.0fixed 2.10.0
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework auth
- affected >= 1.2.0, < 2.10.0fixed 2.10.0
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection option
- affected >= 1.15.0, < 2.10.0fixed 2.10.0
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to inv
- affected >= 2.0.0, < 2.9.0fixed 2.9.0
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, e
- affected >= 1.1.0, < 2.8.0fixed 2.8.0
Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annot
- affected >= 1.20.0, < 2.7.0fixed 2.7.0
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserial
- affected >= 1.10.0, < 2.1.0fixed 2.1.0
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context,
- affected >= 1.10.0, < 1.28.0fixed 1.28.0
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary Java
- affected >= 0.7.0, < 1.24.0fixed 1.24.0
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a
- affected >= 1.21.0, < 1.23.1fixed 1.23.1
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL valid
Page 1 of 2