CVE-2019-10083
published 2019-11-19CVE-2019-10083: When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.75%
84.5th percentile
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.3.0 – 1.9.2 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache5.3
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache NiFi process group information disclosure
osv·2019-12-02
CVE-2019-10083 [MEDIUM] Apache NiFi process group information disclosure
Apache NiFi process group information disclosure
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
GHSA
Apache NiFi process group information disclosure
ghsa·2019-12-02
CVE-2019-10083 [MEDIUM] CWE-200 Apache NiFi process group information disclosure
Apache NiFi process group information disclosure
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Apache
Apache nifi: CVE-2019-10083
vendor_apache·CVSS 5.3
CVE-2019-10083 Apache nifi: CVE-2019-10083
Apache nifi: CVE-2019-10083
Title: Potential Information Disclosure in Process Group Resources Published: 2019-11-04 Severity: Medium Products: Apache NiFi Affected Versions: 1.0.0 to 1.9.2 Fixed Versions: 1.10.0 Reporter: Mark Payne References CVE Record: CVE-2019-10083 NVD Record: CVE-2019-10083 Apache Jira Issue: NIFI-6302 GitHub Pull Request: 3477 When updating a Process Group via the API, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to. Requests to update or remove the process group will no longer return the contents of the process group in the response in Apache NiFi 1.10.0. Users running a prior release should upgrad
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2019-10083https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2019-10083
2019-11-19
Published