PT-2024-35118 · Apache · Apache Nifi
David Handermann
·
Published
2024-11-20
·
Updated
2025-02-11
·
CVE-2024-52067
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/AU:Y/R:U/V:D/RE:L/U:Green |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 1.16.0 through 1.28.0
Apache NiFi versions 2.0.0-M1 through 2.0.0-M4
Description
The issue concerns the optional debug logging of
Parameter Context values during the flow synchronization process in Apache NiFi. An authorized administrator with access to change logging levels could enable debug logging, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on the application flow configuration. Deployments with the default Logback configuration do not log Parameter Context values.Recommendations
For Apache NiFi versions 1.16.0 through 1.28.0, upgrade to Apache NiFi 1.28.1 to eliminate
Parameter value logging from the flow synchronization process.
For Apache NiFi versions 2.0.0-M1 through 2.0.0-M4, upgrade to Apache NiFi 2.0.0 to eliminate Parameter value logging from the flow synchronization process.Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi