CVE-2018-17192
published 2018-12-19CVE-2018-17192: The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would…
PriorityP430medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
2.68%
84.1th percentile
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.0.0 – 1.6.0 | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_apache6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Restriction of Rendered UI Layers or Frames in Apache nifif
osv·2018-12-20
CVE-2018-17192 [MEDIUM] Improper Restriction of Rendered UI Layers or Frames in Apache nifif
Improper Restriction of Rendered UI Layers or Frames in Apache nifif
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
GHSA
Improper Restriction of Rendered UI Layers or Frames in Apache nifif
ghsa·2018-12-20
CVE-2018-17192 [MEDIUM] CWE-1021 Improper Restriction of Rendered UI Layers or Frames in Apache nifif
Improper Restriction of Rendered UI Layers or Frames in Apache nifif
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Apache
Apache nifi: CVE-2018-17192
vendor_apache·CVSS 6.5
CVE-2018-17192 [LOW] Apache nifi: CVE-2018-17192
Apache nifi: CVE-2018-17192
Title: Improper Restriction of Browser Frame Access Published: 2018-10-26 Severity: Low Products: Apache NiFi Affected Versions: 1.0.0 to 1.6.0 Fixed Versions: 1.8.0 Reporter: Suchithra V N References CVE Record: CVE-2018-17192 NVD Record: CVE-2018-17192 Apache Jira Issue: NIFI-5258 GitHub Pull Request: 2759 The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. NiFi 1.8.0 consistently applies the security headers including X-Frame-Options. Users running a prior release should upgrade to 1.8.0.
Severity: low
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-19
Published