Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-52067

Apache NiFi: debug logging can write sensitive Parameter Context values to the application log

Technology

Apache NiFi

CVSS Score

4.9 / 10.0

Affected Versions

1.16.0 to 1.28.0; 2.0.0-M1 to 2.0.0-M4

Upstream Fix

1.28.1; 2.0.0

Published

November 21, 2024

OSSeva Coverage

Fixed upstream

Description

NiFi offers optional debug logging during flow synchronization. An administrator able to change log levels could enable it and cause Parameter names and values, which may be sensitive, to be written to the application log. The default Logback configuration does not log them. Rated medium by the NiFi project. Fixed in 1.28.1 and 2.0.0, which stop logging Parameter values in flow synchronization regardless of the Logback configuration.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.16.0 to 1.28.0; 2.0.0-M1 to 2.0.0-M4, you need this patch. Book a discovery call to get covered.