VYPR

Bitnami package

nifi

pkg:bitnami/nifi

Vulnerabilities (32)

  • CVE-2026-68981HigAug 3, 2026
    affected >= 1.5.0, < 2.11.0fixed 2.11.0

    Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client t

  • CVE-2026-68980CriAug 3, 2026
    affected >= 2.0.0, < 2.11.0fixed 2.11.0

    Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifi

  • CVE-2026-68979CriAug 3, 2026
    affected >= 1.10.0, < 2.11.0fixed 2.11.0

    Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework

  • CVE-2026-62354MedAug 3, 2026
    affected >= 1.10.0, < 2.11.0fixed 2.11.0

    Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined comp

  • CVE-2026-54665MedJun 22, 2026
    affected >= 0.0.1, < 2.10.0fixed 2.10.0

    Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict va

  • CVE-2026-44914HigJun 22, 2026
    affected >= 1.12.0, < 2.10.0fixed 2.10.0

    Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework auth

  • CVE-2026-44913HigJun 22, 2026
    affected >= 1.2.0, < 2.10.0fixed 2.10.0

    Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection option

  • CVE-2026-44911MedJun 22, 2026
    affected >= 1.15.0, < 2.10.0fixed 2.10.0

    Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to inv

  • CVE-2026-39816HigMay 8, 2026
    affected >= 2.0.0, < 2.9.0fixed 2.9.0

    The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, e

  • CVE-2026-25903MedFeb 17, 2026
    affected >= 1.1.0, < 2.8.0fixed 2.8.0

    Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annot

  • CVE-2025-66524HigDec 19, 2025
    affected >= 1.20.0, < 2.7.0fixed 2.7.0

    Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserial

  • CVE-2024-56512MedDec 28, 2024
    affected >= 1.10.0, < 2.1.0fixed 2.1.0

    Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context,

  • CVE-2024-45477MedOct 29, 2024
    affected >= 1.10.0, < 1.28.0fixed 1.28.0

    Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary Java

  • CVE-2023-49145HigNov 27, 2023
    affected >= 0.7.0, < 1.24.0fixed 1.24.0

    Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a

  • CVE-2023-40037MedAug 18, 2023
    affected >= 1.21.0, < 1.23.1fixed 1.23.1

    Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL valid

  • CVE-2023-36542HigJul 29, 2023
    affected >= 0.0.2, <= 1.22.0

    Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Requi

  • CVE-2023-34468HigJun 12, 2023
    affected >= 0.0.2, < 1.22.0fixed 1.22.0

    The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and r

  • CVE-2023-34212MedJun 12, 2023
    affected >= 1.8.0, <= 1.21.0

    The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from

  • CVE-2023-22832HigFeb 10, 2023
    affected >= 1.2.0, <= 1.19.1

    The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with X

  • CVE-2022-33140HigJun 15, 2022
    affected >= 1.10.0, <= 1.16.2

    The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUserGroupProvider is no

Page 1 of 2