GHSA-g644-pr5v-vppf

Suggest an improvement
Source
https://github.com/advisories/GHSA-g644-pr5v-vppf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-g644-pr5v-vppf/GHSA-g644-pr5v-vppf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g644-pr5v-vppf
Aliases
Published
2022-01-06T20:41:02Z
Modified
2024-02-16T08:22:56.559313Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Insertion of Sensitive Information into Log File in Apache NiFi Stateless
Details

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

Database specific
{
    "nvd_published_at": "2020-10-01T20:15:00Z",
    "cwe_ids": [
        "CWE-532"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2021-03-29T16:28:50Z"
}
References

Affected packages

Maven / org.apache.nifi:nifi-stateless

Package

Name
org.apache.nifi:nifi-stateless
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-stateless

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.10.0
Fixed
1.12.0-RC1

Affected versions

1.*

1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4

Database specific

{
    "last_known_affected_version_range": "<= 1.11.4"
}