Количество 2
Количество 2
CVE-2017-5636
больше 8 лет назад
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node.
CVSS3: 9.8
EPSS: Низкий
GHSA-jrcc-7jf5-3pxg
больше 3 лет назад
Injection in Apache NiFi
CVSS3: 9.8
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node. | CVSS3: 9.8 | 1% Низкий | больше 8 лет назад | |
GHSA-jrcc-7jf5-3pxg Injection in Apache NiFi | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20