PT-2024-27515 · Apache · Apache Nifi
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 1.10.0 through 1.26.0
Apache NiFi versions 2.0.0-M1 through 2.0.0-M3
Description
The vulnerability concerns a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user.
Recommendations
For Apache NiFi versions 1.10.0 through 1.26.0, upgrade to Apache NiFi 1.27.0.
For Apache NiFi versions 2.0.0-M1 through 2.0.0-M3, upgrade to Apache NiFi 2.0.0-M4.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi