Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h658-qqv9-qwv8

Опубликовано: 08 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Apache NiFi vulnerable to Cross-site Scripting

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.

Пакеты

Наименование

org.apache.nifi:nifi-web-ui

maven
Затронутые версииВерсия исправления

>= 1.10.0, < 1.27.0

1.27.0

Наименование

org.apache.nifi:nifi-web-ui

maven
Затронутые версииВерсия исправления

>= 2.0.0-M1, < 2.0.0-M4

2.0.0-M4

EPSS

Процентиль: 76%
0.00947
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
больше 1 года назад

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.

EPSS

Процентиль: 76%
0.00947
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79