GHSA-v3vc-6qcv-4vrx

Suggest an improvement
Source
https://github.com/advisories/GHSA-v3vc-6qcv-4vrx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-v3vc-6qcv-4vrx/GHSA-v3vc-6qcv-4vrx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v3vc-6qcv-4vrx
Aliases
Published
2025-02-11T18:31:20Z
Modified
2025-02-11T20:42:22.110416Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/AU:Y/R:U/V:D/RE:L/U:Green CVSS Calculator
Summary
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Details

Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on application flow configuration. Deployments of Apache NiFi with the default Logback configuration do not log Parameter Context values. Upgrading to Apache NiFi 2.0.0 or 1.28.1 is the recommendation mitigation, eliminating Parameter value logging from the flow synchronization process regardless of the Logback configuration.

Database specific
{
    "nvd_published_at": "2024-11-21T11:15:35Z",
    "cwe_ids": [
        "CWE-532"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-02-11T20:10:45Z"
}
References

Affected packages

Maven / org.apache.nifi:nifi-framework-core

Package

Name
org.apache.nifi:nifi-framework-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-framework-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.16.0
Fixed
1.28.1

Affected versions

1.*

1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.18.0
1.19.0
1.19.1
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.23.2
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0

Maven / org.apache.nifi:nifi-framework-core

Package

Name
org.apache.nifi:nifi-framework-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.nifi/nifi-framework-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0-M1
Fixed
2.0.0

Affected versions

2.*

2.0.0-M1
2.0.0-M2
2.0.0-M3
2.0.0-M4

Database specific

{
    "last_known_affected_version_range": "<= 2.0.0-M4"
}