First published: Tue Jan 28 2020(Updated: )
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.nifi:nifi-parameter | =1.10.0 | 1.11.0 |
Apache NiFi | =1.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1928 is an information disclosure vulnerability found in Apache NiFi 1.10.0.
CVE-2020-1928 has a severity rating of 5.3 (medium).
Apache NiFi 1.10.0 is affected by CVE-2020-1928.
To fix CVE-2020-1928, upgrade to Apache NiFi 1.11.0.
Yes, you can find references for CVE-2020-1928 at the following links: [1](https://nvd.nist.gov/vuln/detail/CVE-2020-1928), [2](https://github.com/apache/nifi/commit/42cb6e84898e66672878f61f99543d6af3c0a567), [3](https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e@%3Cusers.tomcat.apache.org%3E).