4.9

CVE-2024-52067

Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log

Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on application flow configuration. Deployments of Apache NiFi with the default Logback configuration do not log Parameter Context values. Upgrading to Apache NiFi 2.0.0 or 1.28.1 is the recommendation mitigation, eliminating Parameter value logging from the flow synchronization process regardless of the Logback configuration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Nifi Version >= 1.16.0 < 1.28.1
Apache ≫ Nifi Version 2.0.0 Update milestone1
Apache ≫ Nifi Version 2.0.0 Update milestone1-rc1
Apache ≫ Nifi Version 2.0.0 Update milestone1-rc2
Apache ≫ Nifi Version 2.0.0 Update milestone1-rc3
Apache ≫ Nifi Version 2.0.0 Update milestone1-rc4
Apache ≫ Nifi Version 2.0.0 Update milestone1-rc5
Apache ≫ Nifi Version 2.0.0 Update milestone1-rc6
Apache ≫ Nifi Version 2.0.0 Update milestone2
Apache ≫ Nifi Version 2.0.0 Update milestone2-rc1
Apache ≫ Nifi Version 2.0.0 Update milestone2-rc2
Apache ≫ Nifi Version 2.0.0 Update milestone2-rc3
Apache ≫ Nifi Version 2.0.0 Update milestone2-rc4
Apache ≫ Nifi Version 2.0.0 Update milestone3
Apache ≫ Nifi Version 2.0.0 Update milestone3-rc1
Apache ≫ Nifi Version 2.0.0 Update milestone4
Apache ≫ Nifi Version 2.0.0 Update milestone4-rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.496
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Apache 6.9 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Green
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://lists.apache.org/thread/9rz5rwn2zc7pfjq7ppqldqlc067tlcwd
Mailing List
http://www.openwall.com/lists/oss-security/2024/11/20/2
Mailing List