CVE-2016-8748: XSS
Published Oct 19, 2017
·Updated
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Affected Software
2 affected components
Apache nifi<=1.0.0
Apache nifi=1.1.0
Event History
Oct 19, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8748?
The severity of CVE-2016-8748 is rated as medium due to the potential impact of the cross-site scripting vulnerability.
2
How do I fix CVE-2016-8748?
To fix CVE-2016-8748, upgrade Apache NiFi to version 1.0.1 or 1.1.1 or later for the affected versions.
3
What are the affected versions for CVE-2016-8748?
CVE-2016-8748 affects Apache NiFi versions before 1.0.1 and 1.1.0.
4
Can CVE-2016-8748 be exploited by unauthorized users?
No, CVE-2016-8748 can only be exploited by authorized users with access to the connection details dialog.
5
What type of vulnerability is CVE-2016-8748?
CVE-2016-8748 is a cross-site scripting (XSS) vulnerability affecting Apache NiFi.