VYPR

Nifi

by Apache

Source repositories

CVEs (54)

  • CVE-2026-54665MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict…

  • CVE-2018-17193MedDec 19, 2018
    risk 0.33cvss 6.1epss 0.03

    The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release.…

  • CVE-2020-13940MedOct 1, 2020
    risk 0.29cvss 5.5epss 0.02

    In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to…

  • CVE-2026-62354MedAug 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined…

  • CVE-2024-56512MedDec 28, 2024
    risk 0.28cvss 5.4epss 0.03

    Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter…

  • CVE-2020-1928MedJan 28, 2020
    risk 0.28cvss 5.3epss 0.04

    An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.

  • CVE-2017-15703MedJan 25, 2018
    risk 0.26cvss 5.0epss 0.01

    Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on the Apache NiFi…

  • CVE-2024-52067MedNov 21, 2024
    risk 0.25cvss 4.9epss 0.01

    Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow…

  • CVE-2024-37389MedJul 8, 2024
    risk 0.25cvss 4.6epss 0.24

    Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code,…

  • CVE-2024-45477MedOct 29, 2024
    risk 0.23cvss 4.6epss 0.01

    Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary…

  • CVE-2022-26850MedApr 6, 2022
    risk 0.21cvss 4.3epss 0.01

    When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permissions. NiFi…

  • CVE-2020-27223MedFeb 26, 2021
    risk 0.06cvss 5.2epss 0.78

    In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU…

  • CVE-2020-1933MedJan 28, 2020
    risk 0.00cvss 6.1epss 0.03

    A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.

  • CVE-2019-10080MedNov 19, 2019
    risk 0.00cvss 6.5epss 0.02

    The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and…

Page 3 of 3