PT-2025-52439 · Apache · Nifi-Asana-Processors-Nar+2

Jaeyeong Lee

·

Published

2025-12-19

·

Updated

2026-01-08

·

CVE-2025-66524

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.20.0 through 2.6.0
Description The GetAsanaObject Processor in Apache NiFi utilizes a Distribute Map Cache Client Service for state management. This processor employs Java Object serialization and deserialization without adequate filtering, creating a potential for exploitation through crafted state information stored in the cache server. Successful exploitation requires access to the configured cache server and an Apache NiFi system running the GetAsanaObject Processor.
Recommendations Upgrade to Apache NiFi version 2.7.0, which replaces Java Object serialization with JSON serialization. Remove the GetAsanaObject Processor located in the nifi-asana-processors-nar bundle.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BIT-NIFI-2025-66524
CVE-2025-66524
GHSA-V4P2-2W39-MHRJ

Affected Products

Apache Nifi
Getasanaobject Processor
Nifi-Asana-Processors-Nar