Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-56512

Apache NiFi: incomplete authorization for parameter and service references

Technology

Apache NiFi

CVSS Score

5.4 / 10.0

Affected Versions

1.10.0 to 2.0.0

Upstream Fix

2.1.0

Published

December 28, 2024

OSSeva Coverage

Fixed upstream

Description

Creating a Process Group did not check authorization for the Parameter Context it was bound to or the Controller Services and Parameter Providers it referenced, so a user allowed to create Process Groups could read non-sensitive parameter values and use components they were not authorised for. It applies only to deployments with component-based policies. Rated low by the NiFi project; NVD scores it 5.4. Fixed in 2.1.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.10.0 to 2.0.0, you need this patch. Book a discovery call to get covered.