PT-2020-15179 · Apache · Apache Nifi

Andy Lopresto

·

Published

2020-02-11

·

Updated

2025-09-12

·

CVE-2020-1942

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 0.0.1 through 1.11.0
Description The issue concerns the flow fingerprint factory in Apache NiFi, which generated flow fingerprints that included sensitive property descriptor values. When a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprints of both the cluster and local flow were printed, potentially exposing sensitive values in plaintext.
Recommendations For Apache NiFi versions 0.0.1 through 1.11.0, consider restricting access to the flow fingerprint factory to minimize the risk of sensitive information exposure until a fix is available.

Fix

Insertion into Log File

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2020-1942
CVE-2020-1942
GHSA-7Q8G-GPFP-V8GX

Affected Products

Apache Nifi