PT-2020-15179 · Apache · Apache Nifi
Andy Lopresto
·
Published
2020-02-11
·
Updated
2025-09-12
·
CVE-2020-1942
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 0.0.1 through 1.11.0
Description
The issue concerns the flow fingerprint factory in Apache NiFi, which generated flow fingerprints that included sensitive property descriptor values. When a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprints of both the cluster and local flow were printed, potentially exposing sensitive values in plaintext.
Recommendations
For Apache NiFi versions 0.0.1 through 1.11.0, consider restricting access to the flow fingerprint factory to minimize the risk of sensitive information exposure until a fix is available.
Fix
Insertion into Log File
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Nifi