PT-2018-13946 · Apache · Apache Nifi
Mike Cole
·
Published
2018-12-19
·
Updated
2020-08-24
·
CVE-2018-17195
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions prior to 1.8.0
Description
The template upload API endpoint is susceptible to a CSRF attack when combined with ARP spoofing and a man-in-the-middle (MiTM) attack. This complex attack vector requires client certificate authentication, same subnet access, and the injection of malicious code into an unprotected website that the targeted user later visits. The potential damage from this attack warrants a severe severity level.
Recommendations
For Apache NiFi versions prior to 1.8.0, upgrade to version 1.8.0 or later to apply the Cross-Origin Resource Sharing (CORS) policy request filtering fix.
Fix
Cleartext Transmission of Sensitive Information
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Nifi