CVE-2017-7665
published 2017-06-12CVE-2017-7665: In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but…
PriorityP426medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
3.51%
87.8th percentile
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | <= 0.7.3 | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_apache6.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site Scripting in Apache NiFi
osv·2022-05-17
CVE-2017-7665 [MEDIUM] Cross-site Scripting in Apache NiFi
Cross-site Scripting in Apache NiFi
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
GHSA
Cross-site Scripting in Apache NiFi
ghsa·2022-05-17
CVE-2017-7665 [MEDIUM] CWE-79 Cross-site Scripting in Apache NiFi
Cross-site Scripting in Apache NiFi
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
Apache
Apache nifi: CVE-2017-7665
vendor_apache·CVSS 6.1
CVE-2017-7665 Apache nifi: CVE-2017-7665
Apache nifi: CVE-2017-7665
Title: Potential Cross-Site Scripting in User Interface Components Published: 2017-05-08 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.1 to 0.7.3 and 1.0.0 to 1.2.0 Fixed Versions: 0.7.4 and 1.3.0 Reporter: Matt Gilman References CVE Record: CVE-2017-7665 NVD Record: CVE-2017-7665 Apache Jira Issue: NIFI-3906 GitHub Pull Request: 1818 There are certain user input components in the Apache NiFi UI which had been guarding for some forms of cross-site scripting issues but were insufficient. NiFi 0.7.4 and 1.3.0 add more complete user input sanitization. Users running a prior release should upgrade to 0.7.4 or 1.3.0.
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99009https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3Ehttp://www.securityfocus.com/bid/99009https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3E
2017-06-12
Published