Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-27017

Apache NiFi: MongoDB password can be written to a provenance record

Technology

Apache NiFi

CVSS Score

6.5 / 10.0

Affected Versions

1.13.0 to 2.2.0

Upstream Fix

2.3.0

Published

March 12, 2025

OSSeva Coverage

Fixed upstream

Description

Provenance events generated by MongoDB components included the username and password used to connect to MongoDB, so users with read access to those events could see the credentials. Rated medium by the NiFi project. Fixed in 2.3.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.13.0 to 2.2.0, you need this patch. Book a discovery call to get covered.