PT-2024-10215 · Apache · Apache Nifi

Matt Gilman

·

Published

2024-12-26

·

Updated

2025-09-12

·

CVE-2024-56512

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.10.0 through 2.0.0
Description The issue is related to missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers when creating new Process Groups. This allows clients to download non-sensitive Parameter values after creating the Process Group and enables clients to create Process Groups and use these components that were otherwise unauthorized. The scope is limited to authenticated users authorized to create Process Groups and deployments with component-based authorization policies.
Recommendations Upgrading to Apache NiFi 2.1.0 is the recommended mitigation, which includes authorization checking for Parameter and Controller Service references on Process Group creation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-00545
BIT-NIFI-2024-56512
CVE-2024-56512
GHSA-MPJ7-7MG7-X95J

Affected Products

Apache Nifi