CVE-2026-68981
- EPSS 0.32%
- Veröffentlicht 03.08.2026 19:59:58
- Zuletzt bearbeitet 05.08.2026 14:59:30
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output,...
CVE-2026-68980
- EPSS 0.26%
- Veröffentlicht 03.08.2026 19:58:56
- Zuletzt bearbeitet 05.08.2026 14:59:19
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context...
CVE-2026-62354
- EPSS 0.31%
- Veröffentlicht 03.08.2026 19:57:44
- Zuletzt bearbeitet 10.08.2026 14:28:56
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read ac...
CVE-2026-68979
- EPSS 0.35%
- Veröffentlicht 03.08.2026 19:56:11
- Zuletzt bearbeitet 05.08.2026 14:59:03
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referen...
CVE-2026-44914
- EPSS 0.29%
- Veröffentlicht 22.06.2026 07:38:01
- Zuletzt bearbeitet 24.06.2026 05:17:28
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privilege...
CVE-2026-44911
- EPSS 0.26%
- Veröffentlicht 22.06.2026 07:37:10
- Zuletzt bearbeitet 23.06.2026 19:55:10
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling...
CVE-2026-44913
- EPSS 0.26%
- Veröffentlicht 22.06.2026 07:36:40
- Zuletzt bearbeitet 23.06.2026 19:53:00
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope...
CVE-2026-54665
- EPSS 0.19%
- Veröffentlicht 22.06.2026 07:34:13
- Zuletzt bearbeitet 23.06.2026 19:19:18
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable appli...
CVE-2026-39816
- EPSS 0.76%
- Veröffentlicht 08.05.2026 13:38:12
- Zuletzt bearbeitet 09.05.2026 02:16:07
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for...
CVE-2026-25903
- EPSS 0.75%
- Veröffentlicht 17.02.2026 10:15:57
- Zuletzt bearbeitet 30.03.2026 15:20:58
Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privil...