Vulnerabilities (CVE)

Vendor filter

Apache Subscribe

Product filter

Nifi Subscribe


13 total CVE
CVE Vendors Products Updated CVSS
CVE-2016-8748 1 Apache 1 Nifi 2019-05-01 3.5
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
CVE-2018-17193 1 Apache 1 Nifi 2019-02-07 4.3
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on...
CVE-2018-17194 1 Apache 1 Nifi 2019-01-11 5.0
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than...
CVE-2018-17195 1 Apache 1 Nifi 2019-01-11 5.1
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with...
CVE-2018-17192 1 Apache 1 Nifi 2019-01-11 4.3
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to...
CVE-2018-1309 1 Apache 1 Nifi 2018-06-27 7.5
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on...
CVE-2018-1310 1 Apache 1 Nifi 2018-06-26 5.0
Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to...
CVE-2017-12632 1 Apache 1 Nifi 2018-02-13 5.0
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a...
CVE-2017-5636 1 Apache 1 Nifi 2017-11-07 7.5
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their...
CVE-2017-5635 1 Apache 1 Nifi 2017-11-07 5.0
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
CVE-2017-12623 1 Apache 1 Nifi 2017-11-05 4.0
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users...
CVE-2017-7665 1 Apache 1 Nifi 2017-06-19 4.3
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
CVE-2017-7667 1 Apache 1 Nifi 2017-06-19 5.0
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.