https://seclists.org/oss-sec/2024/q4/41: CVE-2024-45477: Apache NiFi: Improper Neutralization of Input in Parameter Description
Published Oct 28, 2024
·Updated
Affected Software
2 affected components
Apache nifi>=1.10.0<=1.27.0
Apache nifi>=2.0.0-M1<=2.0.0-M3
Frequently Asked Questions
1
What is the severity of CVE-2024-45477?
CVE-2024-45477 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-45477?
To mitigate CVE-2024-45477, upgrade to Apache NiFi version 1.27.1 or later, or 2.0.0-M4 or later.
3
Which versions of Apache NiFi are affected by CVE-2024-45477?
CVE-2024-45477 affects Apache NiFi versions 1.10.0 through 1.27.0 and 2.0.0-M1 to 2.0.0-M3.
4
What impact does CVE-2024-45477 have on users?
The vulnerability allows an attacker to execute arbitrary scripts in a user's browser through cross-site scripting, compromising user data.
5
Is there a workaround for CVE-2024-45477 before upgrading?
There is no official workaround for CVE-2024-45477; upgrading to a secure version is the recommended action.