CVE-2017-7665: XSS
Published Jun 12, 2017
·Updated
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
Affected Software
7 affected components
Apache nifi<=0.7.3
Apache nifi=1.0.0
Apache nifi=1.0.1
Apache nifi=1.1.0
Apache nifi=1.1.1
Apache nifi=1.1.2
Apache nifi=1.2.0
Event History
Jun 12, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7665?
The severity of CVE-2017-7665 is classified as Medium due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-7665?
To fix CVE-2017-7665, upgrade Apache NiFi to version 1.3.0 or later.
3
What versions of Apache NiFi are affected by CVE-2017-7665?
Apache NiFi versions before 0.7.4 and 1.x versions prior to 1.3.0 are affected by CVE-2017-7665.
4
What type of vulnerability is CVE-2017-7665?
CVE-2017-7665 is a cross-site scripting (XSS) vulnerability affecting Apache NiFi.
5
Is user input in Apache NiFi's UI safe in versions before the patch for CVE-2017-7665?
No, user input in Apache NiFi's UI is not safe in versions before the patch for CVE-2017-7665 due to insufficient guarding against XSS.