https://seclists.org/oss-sec/2024/q3/29: CVE-2024-37389: Apache NiFi: Improper Neutralization of Input in Parameter Context Description
Published Jul 8, 2024
·Updated
Affected Software
2 affected components
Apache nifi>=1.10.0<=1.26.0
Apache nifi>=2.0.0-M1<=2.0.0-M3
Frequently Asked Questions
1
What is the severity of CVE-2024-37389?
CVE-2024-37389 has a high severity due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-37389?
To fix CVE-2024-37389, upgrade to Apache NiFi version 1.26.1 or 2.0.0-M4 or later that addresses the vulnerability.
3
Which versions of Apache NiFi are affected by CVE-2024-37389?
Apache NiFi versions 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 are affected by CVE-2024-37389.
4
What type of vulnerability does CVE-2024-37389 represent?
CVE-2024-37389 represents a cross-site scripting vulnerability due to improper neutralization of input in the Parameter Context description.
5
Is authentication required to exploit CVE-2024-37389?
Yes, exploitation of CVE-2024-37389 requires an authenticated user to inject malicious scripts.