PT-2018-13946 · Apache · Apache Nifi

Mike Cole

·

Published

2018-12-19

·

Updated

2020-08-24

·

CVE-2018-17195

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NiFi versions prior to 1.8.0
Description The template upload API endpoint is susceptible to a CSRF attack when combined with ARP spoofing and a man-in-the-middle (MiTM) attack. This complex attack vector requires client certificate authentication, same subnet access, and the injection of malicious code into an unprotected website that the targeted user later visits. The potential damage from this attack warrants a severe severity level.
Recommendations For Apache NiFi versions prior to 1.8.0, upgrade to version 1.8.0 or later to apply the Cross-Origin Resource Sharing (CORS) policy request filtering fix.

Fix

Cleartext Transmission of Sensitive Information

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17195
GHSA-3JQ8-JG75-RQV6

Affected Products

Apache Nifi