First published: Mon Jun 12 2017(Updated: )
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache NiFi | <=0.7.3 | |
Apache NiFi | =1.0.0 | |
Apache NiFi | =1.0.1 | |
Apache NiFi | =1.1.0 | |
Apache NiFi | =1.1.1 | |
Apache NiFi | =1.1.2 | |
Apache NiFi | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-7665 is classified as Medium due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2017-7665, upgrade Apache NiFi to version 1.3.0 or later.
Apache NiFi versions before 0.7.4 and 1.x versions prior to 1.3.0 are affected by CVE-2017-7665.
CVE-2017-7665 is a cross-site scripting (XSS) vulnerability affecting Apache NiFi.
No, user input in Apache NiFi's UI is not safe in versions before the patch for CVE-2017-7665 due to insufficient guarding against XSS.