VYPR

Nifi

by Apache

Source repositories

CVEs (54)

  • CVE-2021-20190HigJan 19, 2021
    risk 0.46cvss 8.1epss 0.07

    A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2023-49145HigNov 27, 2023
    risk 0.44cvss 7.9epss 0.01

    Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits…

  • CVE-2023-22832HigFeb 10, 2023
    risk 0.42cvss 7.5epss 0.01

    The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with…

  • CVE-2021-44145MedDec 17, 2021
    risk 0.42cvss 6.5epss 0.02

    In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.

  • CVE-2020-9491HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and…

  • CVE-2020-9487HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly…

  • CVE-2020-9486HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.04

    In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

  • CVE-2020-1942HigFeb 11, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and…

  • CVE-2018-17195HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.01

    The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication,…

  • CVE-2018-17194HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait…

  • CVE-2017-12623MedOct 10, 2017
    risk 0.42cvss 6.5epss 0.02

    An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should…

  • CVE-2026-44911MedJun 22, 2026
    risk 0.41cvss 6.3epss 0.00

    Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to…

  • CVE-2017-7665MedJun 12, 2017
    risk 0.40cvss 6.1epss 0.04

    In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.

  • CVE-2026-25903MedFeb 17, 2026
    risk 0.36cvss 6.6epss 0.01

    Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the…

  • CVE-2025-27017MedMar 12, 2025
    risk 0.35cvss 6.5epss 0.01

    Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those processors may see the…

  • CVE-2023-40037MedAug 18, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL…

  • CVE-2023-34212MedJun 12, 2023
    risk 0.35cvss 6.5epss 0.02

    The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from…

  • CVE-2019-10083MedNov 19, 2019
    risk 0.35cvss 5.3epss 0.03

    When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had…

  • CVE-2018-17192MedDec 19, 2018
    risk 0.35cvss 6.5epss 0.03

    The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security…

  • CVE-2016-8748MedOct 19, 2017
    risk 0.35cvss 5.4epss 0.02

    In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.