Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g644-pr5v-vppf

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Insertion of Sensitive Information into Log File in Apache NiFi Stateless

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

Пакеты

Наименование

org.apache.nifi:nifi-stateless

maven
Затронутые версииВерсия исправления

>= 1.10.0, <= 1.11.4

1.12.0-RC1

EPSS

Процентиль: 68%
0.0058
Низкий

7.5 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

EPSS

Процентиль: 68%
0.0058
Низкий

7.5 High

CVSS3

Дефекты

CWE-532