VYPR

Bitnami package

nifi

pkg:bitnami/nifi

Vulnerabilities (24)

  • CVE-2020-9486Oct 1, 2020
    affected >= 1.0.0, <= 1.11.4

    In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

  • CVE-2020-1942Feb 11, 2020
    affected >= 0.0.1, <= 1.11.0

    In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and loc

  • CVE-2020-1933Jan 28, 2020
    affected >= 1.0.0, <= 1.10.0

    A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.

  • CVE-2020-1928Jan 28, 2020
    affected >= 1.10.0, <= 1.10.0

    An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.

Page 2 of 2