CVE-2024-52067
Apache NiFi: debug logging can write sensitive Parameter Context values to the application log
Technology
Apache NiFi
CVSS Score
4.9 / 10.0
Affected Versions
1.16.0 to 1.28.0; 2.0.0-M1 to 2.0.0-M4
Upstream Fix
1.28.1; 2.0.0
Published
November 21, 2024
OSSeva Coverage
Fixed upstream
Description
NiFi offers optional debug logging during flow synchronization. An administrator able to change log levels could enable it and cause Parameter names and values, which may be sensitive, to be written to the application log. The default Logback configuration does not log them. Rated medium by the NiFi project. Fixed in 1.28.1 and 2.0.0, which stop logging Parameter values in flow synchronization regardless of the Logback configuration.
Is your Apache NiFi deployment affected?
If you're running 1.16.0 to 1.28.0; 2.0.0-M1 to 2.0.0-M4, you need this patch. Book a discovery call to get covered.