https://seclists.org/oss-sec/2025/q1/199: CVE-2025-27017: Apache NiFi: Potential Insertion of MongoDB Password in Provenance cord
Published Mar 11, 2025
·Updated
Affected Software
1 affected component
Apache nifi>=1.13.0<=2.2.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27017?
CVE-2025-27017 is categorized as a high-severity vulnerability due to the exposure of sensitive MongoDB credentials.
2
How do I fix CVE-2025-27017?
To fix CVE-2025-27017, upgrade Apache NiFi to version 2.3.0 or later, which does not include the sensitive information in provenance events.
3
Who is affected by CVE-2025-27017?
Users of Apache NiFi versions 1.13.0 through 2.2.0 are affected by CVE-2025-27017.
4
What data is exposed in CVE-2025-27017?
CVE-2025-27017 exposes MongoDB usernames and passwords used for authentication in provenance events.
5
Is Apache NiFi version 2.3.0 vulnerable to CVE-2025-27017?
No, Apache NiFi version 2.3.0 is unaffected by CVE-2025-27017.