CVE-2020-9487: High severity apache nifi vulnerability
Published Oct 1, 2020
·Updated
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly request download tokens, preventing legitimate users from requesting download tokens.
Affected Software
1 affected component
Apache nifi>=1.0.0<=1.11.4
Event History
Oct 1, 2020
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-9487?
CVE-2020-9487 is a vulnerability in Apache NiFi 1.0.0 to 1.11.4.
2
How does CVE-2020-9487 affect Apache NiFi?
CVE-2020-9487 affects Apache NiFi versions 1.0.0 to 1.11.4.
3
What is the severity level of CVE-2020-9487?
The severity level of CVE-2020-9487 is high (7.5).
4
How does CVE-2020-9487 work?
CVE-2020-9487 allows an unauthenticated user to repeatedly request download tokens, potentially bypassing authentication.
5
What should I do to fix CVE-2020-9487?
To fix CVE-2020-9487, upgrade your Apache NiFi installation to a version later than 1.11.4.