Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Leonardo Dias

#37353of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2017-16635
7.5
2017-10-19
Apache · Apache Nifi · CVE-2017-5635
**Name of the Vulnerable Software and Affected Versions** Apache NiFi versions prior to 0.7.2 Apache NiFi versions 1.x prior to 1.1.2 **Description** The issue arises in a cluster environment when an anonymous user request is replicated to another node. Instead of using the "anonymous" user identity, the system uses the identity of the originating node. **Recommendations** For Apache NiFi versions prior to 0.7.2, update to version 0.7.2 or later. For Apache NiFi versions 1.x prior to 1.1.2, update to version 1.1.2 or later.