Vulnerabilities > Apache > Nifi > 1.2.0

DATE CVE VULNERABILITY TITLE RISK
2023-11-27 CVE-2023-49145 Cross-site Scripting vulnerability in Apache Nifi
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting.
network
low complexity
apache CWE-79
5.4
2023-07-29 CVE-2023-36542 Code Injection vulnerability in Apache Nifi
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution.
network
low complexity
apache CWE-94
8.8
2023-02-10 CVE-2023-22832 XXE vulnerability in Apache Nifi
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.
network
low complexity
apache CWE-611
7.5
2022-04-30 CVE-2022-29265 XXE vulnerability in Apache Nifi
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration.
network
low complexity
apache CWE-611
5.0
2021-12-17 CVE-2021-44145 Information Exposure vulnerability in Apache Nifi
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
network
low complexity
apache CWE-200
4.0
2020-10-01 CVE-2020-9491 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Apache Nifi
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc.
network
low complexity
apache CWE-327
7.5
2020-10-01 CVE-2020-9487 Missing Authentication for Critical Function vulnerability in Apache Nifi
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content.
network
low complexity
apache CWE-306
5.0
2020-10-01 CVE-2020-9486 Information Exposure Through Log Files vulnerability in Apache Nifi
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values.
network
low complexity
apache CWE-532
5.0
2020-10-01 CVE-2020-13940 XXE vulnerability in Apache Nifi
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file.
network
apache CWE-611
4.3
2020-02-11 CVE-2020-1942 Information Exposure vulnerability in Apache Nifi
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values.
network
low complexity
apache CWE-200
5.0