CVE-2020-9486: High severity apache nifi vulnerability
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9486?
The severity of CVE-2020-9486 is high with a severity value of 7.5.
How does Apache NiFi 1.10.0 to 1.11.4 handle sensitive property values in log output?
Apache NiFi 1.10.0 to 1.11.4 may include sensitive property values in plaintext in the log output.
What version of Apache NiFi fixes CVE-2020-9486?
CVE-2020-9486 is fixed in Apache NiFi version 1.12.0-RC1.
Where can I find more information about CVE-2020-9486?
You can find more information about CVE-2020-9486 on the NVD website (https://nvd.nist.gov/vuln/detail/CVE-2020-9486), in the Apache NiFi GitHub commit (https://github.com/apache/nifi/commit/148537d64a017b73160b0d49943183c18f883ab0), and on the Apache NiFi security page (https://nifi.apache.org/security#CVE-2020-9486).
What is the CWE ID for CVE-2020-9486?
The CWE ID for CVE-2020-9486 is 532.