Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68pr-6fjc-wmgm

Опубликовано: 28 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.9

Описание

Improper Neutralization of Input in Advanced User Interface for Jolt

Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.

Пакеты

Наименование

org.apache.nifi:nifi-jolt-transform-json-ui

maven
Затронутые версииВерсия исправления

< 1.24.0

1.24.0

EPSS

Процентиль: 52%
0.00293
Низкий

7.9 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.9
nvd
около 2 лет назад

Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.

CVSS3: 7.9
fstec
около 2 лет назад

Уязвимость компонента JoltTransform платформы обработки данных Apache NiFi, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

EPSS

Процентиль: 52%
0.00293
Низкий

7.9 High

CVSS3

Дефекты

CWE-79