Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2017-5636

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain…

Technology

Apache NiFi

CVSS Score

9.8 / 10.0

Affected Versions

0.7.0; 0.7.1; 1.1.0; 1.1.1

Upstream Fix

See upstream advisory

Published

October 19, 2017

OSSeva Coverage

Fixed upstream

Description

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node.

Is your Apache NiFi deployment affected?

If you're running 0.7.0; 0.7.1; 1.1.0; 1.1.1, you need this patch. Book a discovery call to get covered.