First published: Mon Jun 12 2017(Updated: )
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache NiFi | <=0.7.3 | |
Apache NiFi | =1.0.0 | |
Apache NiFi | =1.0.1 | |
Apache NiFi | =1.1.0 | |
Apache NiFi | =1.1.1 | |
Apache NiFi | =1.1.2 | |
Apache NiFi | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7667 has a medium severity rating due to the risk of clickjacking attacks.
To fix CVE-2017-7667, update Apache NiFi to version 0.7.4 or 1.3.0 or later.
CVE-2017-7667 affects Apache NiFi versions prior to 0.7.4 and all 1.x versions before 1.3.0.
CVE-2017-7667 exposes users to potential clickjacking attacks due to improper frame handling.
There is no specific known workaround for CVE-2017-7667 besides upgrading to a patched version.