Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7667.json"