CVE-2017-5635
published 2017-10-19CVE-2017-5635: In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
3.29%
87.1th percentile
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authentication In Apache NiFi
osv·2022-05-13
CVE-2017-5635 [HIGH] Improper Authentication In Apache NiFi
Improper Authentication In Apache NiFi
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
GHSA
Improper Authentication In Apache NiFi
ghsa·2022-05-13
CVE-2017-5635 [HIGH] CWE-287 Improper Authentication In Apache NiFi
Improper Authentication In Apache NiFi
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
Apache
Apache nifi: CVE-2017-5635
vendor_apache·CVSS 7.5
CVE-2017-5635 Apache nifi: CVE-2017-5635
Apache nifi: CVE-2017-5635
Title: Improper Authentication of Replicated Cluster HTTP Requests Published: 2017-02-20 Severity: Medium Products: Apache NiFi Affected Versions: 0.7.0 to 0.7.1 and 1.1.0 to 1.1.1 Fixed Versions: 0.7.2 and 1.1.2 Reporter: Leonardo Dias and Matt Gilman References CVE Record: CVE-2017-5635 NVD Record: CVE-2017-5635 Apache Jira Issue: NIFI-3487 In a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the anonymous user. NiFi 0.7.2 and 1.1.2 remove the negative check for anonymous user before building the proxy chain and throwing an exception, and evaluating each user in the proxy chain iteration and comparing against a static constant anonymous user. Users running a prior release should
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-19
Published