Vulnerabilities > Apache > Nifi > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-45477 Cross-site Scripting vulnerability in Apache Nifi
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting.
network
low complexity
apache CWE-79
4.6
2024-07-08 CVE-2024-37389 Cross-site Scripting vulnerability in Apache Nifi
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting.
network
low complexity
apache CWE-79
5.4
2023-11-27 CVE-2023-49145 Cross-site Scripting vulnerability in Apache Nifi
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting.
network
low complexity
apache CWE-79
5.4
2023-08-18 CVE-2023-40037 Incorrect Comparison vulnerability in Apache Nifi 1.21.0/1.22.0/1.23.0
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs.
network
low complexity
apache CWE-697
6.5
2023-06-12 CVE-2023-34212 Deserialization of Untrusted Data vulnerability in Apache Nifi
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
network
low complexity
apache CWE-502
6.5
2022-04-06 CVE-2022-26850 Exposure of Resource to Wrong Sphere vulnerability in Apache Nifi 1.14.0/1.15.0/1.15.3
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory.
network
low complexity
apache CWE-668
4.3
2021-12-17 CVE-2021-44145 Information Exposure vulnerability in Apache Nifi
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.
network
low complexity
apache CWE-200
6.5
2021-02-26 CVE-2020-27223 Resource Exhaustion vulnerability in multiple products
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e.
network
low complexity
eclipse apache netapp debian oracle CWE-400
5.3
2020-10-01 CVE-2020-13940 XXE vulnerability in Apache Nifi
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file.
local
low complexity
apache CWE-611
5.5
2020-01-28 CVE-2020-1933 Cross-site Scripting vulnerability in Apache Nifi
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0.
network
low complexity
apache CWE-79
6.1