CVE-2017-7667
published 2017-06-12CVE-2017-7667: Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.43%
69.9th percentile
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | <= 0.7.3 | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Origin Validation Error in Apache NiFi
osv·2022-05-17
CVE-2017-7667 [HIGH] Origin Validation Error in Apache NiFi
Origin Validation Error in Apache NiFi
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
GHSA
Origin Validation Error in Apache NiFi
ghsa·2022-05-17
CVE-2017-7667 [HIGH] CWE-346 Origin Validation Error in Apache NiFi
Origin Validation Error in Apache NiFi
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
Apache
Apache nifi: CVE-2017-7667
vendor_apache·CVSS 7.5
CVE-2017-7667 Apache nifi: CVE-2017-7667
Apache nifi: CVE-2017-7667
Title: Potential Cross-Frame Scripting from Improper Frame Access Restrictions Published: 2017-05-08 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.1 to 0.7.3 and 1.0.0 to 1.2.0 Fixed Versions: 0.7.4 and 1.3.0 Reporter: Matt Gilman References CVE Record: CVE-2017-7667 NVD Record: CVE-2017-7667 Apache Jira Issue: NIFI-3907 Apache NiFi needs to establish the response header telling browsers to only allow framing with the same origin. NiFi 0.7.4 and 1.3.0 set the response header. Users running a prior release should upgrade to 0.7.4 or 1.3.0.
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99018https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3Ehttp://www.securityfocus.com/bid/99018https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3E
2017-06-12
Published