In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
2017-06-12T16:29:00.217
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | nifi | ≤ 0.7.3 | Yes |
Application | apache | nifi | 1.0.0 | Yes |
Application | apache | nifi | 1.0.1 | Yes |
Application | apache | nifi | 1.1.0 | Yes |
Application | apache | nifi | 1.1.1 | Yes |
Application | apache | nifi | 1.1.2 | Yes |
Application | apache | nifi | 1.2.0 | Yes |