CVE-2020-1942: Infoleak
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.nifi:nifi-security-utilsto a version that resolves this vulnerability.Fixed in 1.12.0-RC1 - Upgrade
Upgrade
maven/org.apache.nifi:nifi-framework-coreto a version that resolves this vulnerability.Fixed in 1.12.0-RC1
Event History
Frequently Asked Questions
What is CVE-2020-1942?
CVE-2020-1942 is a vulnerability in Apache NiFi versions 0.0.1 to 1.11.0 that exposes sensitive property descriptor values in generated flow fingerprints.
What is the severity of CVE-2020-1942?
CVE-2020-1942 has a severity rating of 7.5 (High).
How does CVE-2020-1942 affect Apache NiFi?
CVE-2020-1942 affects Apache NiFi versions 0.0.1 to 1.11.0 by exposing sensitive property descriptor values in generated flow fingerprints, leading to potential information disclosure.
How can I fix CVE-2020-1942?
To fix CVE-2020-1942, upgrade to Apache NiFi version 1.12.0-RC1 or later.
Where can I find more information about CVE-2020-1942?
You can find more information about CVE-2020-1942 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-1942), [GitHub Commit 1](https://github.com/apache/nifi/commit/95746d346cddbd6134c4b28fdc39d5813a626f97), [GitHub Commit 2](https://github.com/apache/nifi/commit/d7c29f46378379fb596e4d1e59d1a3c41063db5b).