First published: Tue Feb 11 2020(Updated: )
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache NiFi | >=0.0.1<=1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1942 is a vulnerability in Apache NiFi versions 0.0.1 to 1.11.0 that exposes sensitive property descriptor values in generated flow fingerprints.
CVE-2020-1942 has a severity rating of 7.5 (High).
CVE-2020-1942 affects Apache NiFi versions 0.0.1 to 1.11.0 by exposing sensitive property descriptor values in generated flow fingerprints, leading to potential information disclosure.
To fix CVE-2020-1942, upgrade to Apache NiFi version 1.12.0-RC1 or later.
You can find more information about CVE-2020-1942 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-1942), [GitHub Commit 1](https://github.com/apache/nifi/commit/95746d346cddbd6134c4b28fdc39d5813a626f97), [GitHub Commit 2](https://github.com/apache/nifi/commit/d7c29f46378379fb596e4d1e59d1a3c41063db5b).