CVE-2025-27017
- EPSS 0.08%
- Published 12.03.2025 16:19:45
- Last modified 16.07.2025 14:45:49
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of th...
CVE-2024-56512
- EPSS 27.78%
- Published 28.12.2024 17:15:07
- Last modified 11.02.2025 16:10:28
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include b...
CVE-2024-52067
- EPSS 0.19%
- Published 21.11.2024 11:15:35
- Last modified 11.02.2025 16:26:42
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug lo...
CVE-2024-45477
- EPSS 0.3%
- Published 29.10.2024 09:15:07
- Last modified 21.11.2024 09:37:50
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Con...
CVE-2024-37389
- EPSS 0.81%
- Published 08.07.2024 08:15:10
- Last modified 21.11.2024 09:23:46
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can ent...
CVE-2023-49145
- EPSS 0.29%
- Published 27.11.2023 23:15:07
- Last modified 21.11.2024 08:32:55
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTra...
CVE-2023-40037
- EPSS 1.76%
- Published 18.08.2023 22:15:10
- Last modified 13.02.2025 17:17:00
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user c...
CVE-2023-36542
- EPSS 0.94%
- Published 29.07.2023 08:15:48
- Last modified 13.02.2025 17:16:42
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The res...
CVE-2023-34468
- EPSS 78.61%
- Published 12.06.2023 16:15:10
- Last modified 13.02.2025 17:16:38
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution va...
CVE-2023-34212
- EPSS 1.11%
- Published 12.06.2023 16:15:10
- Last modified 13.02.2025 17:16:35
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deseriali...