[MAVEN:GHSA-G644-PR5V-VPPF] Insertion of Sensitive Information into Log File in Apache NiFi Stateless

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

Package Affected Version
pkg:maven/org.apache.nifi/nifi-stateless >= 1.10.0, <= 1.11.4
Package Fixed Version
pkg:maven/org.apache.nifi/nifi-stateless = 1.12.0-RC1
ID
MAVEN:GHSA-G644-PR5V-VPPF
Severity
high
URL
https://github.com/advisories/GHSA-g644-pr5v-vppf
Published
2022-01-06T20:41:02
(2 years ago)
Modified
2023-09-12T15:04:26
(12 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.nifi/nifi-stateless org.apache.nifi nifi-stateless >= 1.10.0 <= 1.11.4
Fixed pkg:maven/org.apache.nifi/nifi-stateless org.apache.nifi nifi-stateless = 1.12.0-RC1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...