CVE-2020-1928: Infoleak
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.nifi:nifi-parameterto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is CVE-2020-1928?
CVE-2020-1928 is an information disclosure vulnerability found in Apache NiFi 1.10.0.
How severe is CVE-2020-1928?
CVE-2020-1928 has a severity rating of 5.3 (medium).
What software versions are affected by CVE-2020-1928?
Apache NiFi 1.10.0 is affected by CVE-2020-1928.
How do I fix CVE-2020-1928?
To fix CVE-2020-1928, upgrade to Apache NiFi 1.11.0.
Are there any references for CVE-2020-1928?
Yes, you can find references for CVE-2020-1928 at the following links: [1](https://nvd.nist.gov/vuln/detail/CVE-2020-1928), [2](https://github.com/apache/nifi/commit/42cb6e84898e66672878f61f99543d6af3c0a567), [3](https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e@%3Cusers.tomcat.apache.org%3E).