CVE-2016-8748
published 2017-10-19CVE-2016-8748: In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized…
PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.76%
75.4th percentile
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | <= 1.0.0 | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_apache5.4
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2016-8748
vendor_apache·CVSS 5.4
CVE-2016-8748 Apache nifi: CVE-2016-8748
Apache nifi: CVE-2016-8748
Title: Potential Cross-Site Scripting in Connection Details Dialog Published: 2016-12-19 Severity: Medium Products: Apache NiFi Affected Versions: 1.0.0 and 1.1.0 Fixed Versions: 1.0.1 and 1.1.1 Reporter: Matt Gilman References CVE Record: CVE-2016-8748 NVD Record: CVE-2016-8748 Apache Jira Issue: NIFI-3154 GitHub Pull Request: 1305 There is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM. The vulnerability was resolved after reviewing the pull request when merging changes. Users running a prior release should upgrade to 1.0.1 or 1.1.1.
Severity: moderate
OSV
Cross-site Scripting in Apache NiFi
osv·2022-05-14
CVE-2016-8748 [MEDIUM] Cross-site Scripting in Apache NiFi
Cross-site Scripting in Apache NiFi
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
GHSA
Cross-site Scripting in Apache NiFi
ghsa·2022-05-14
CVE-2016-8748 [MEDIUM] CWE-79 Cross-site Scripting in Apache NiFi
Cross-site Scripting in Apache NiFi
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
No detection rules found.
No public exploits indexed.
2017-10-19
Published