PT-2017-17873 · Apache · Apache Nifi

Published

2017-06-12

·

Updated

2022-05-17

·

CVE-2017-7667

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions prior to 0.7.4 Apache NiFi 1.x versions prior to 1.3.0
Description The issue arises from Apache NiFi's failure to establish a response header that instructs browsers to only allow framing from the same origin. This could potentially lead to security issues related to framing.
Recommendations For Apache NiFi versions prior to 0.7.4, update to version 0.7.4 or later. For Apache NiFi 1.x versions prior to 1.3.0, update to version 1.3.0 or later.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7667
GHSA-JVX9-RJ3W-JQ99

Affected Products

Apache Nifi