Описание
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
Ссылки
- Third Party AdvisoryVDB Entry
- Issue TrackingMitigationVendor Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:apache:nifi:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:nifi:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:nifi:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:nifi:1.1.1:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01131
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
EPSS
Процентиль: 78%
0.01131
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287