CVE-2019-12421
published 2019-11-19CVE-2019-12421: When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.85%
76.6th percentile
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.0.0 – 1.9.2 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_apache8.8
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2019-12421
vendor_apache·CVSS 8.8
CVE-2019-12421 Apache nifi: CVE-2019-12421
Apache nifi: CVE-2019-12421
Title: Application Bearer Token Remains Valid After Logout Completion Published: 2019-11-04 Severity: Medium Products: Apache NiFi Affected Versions: 1.0.0 to 1.9.2 Fixed Versions: 1.10.0 Reporter: Abdu Sahin References CVE Record: CVE-2019-12421 NVD Record: CVE-2019-12421 Apache Jira Issue: NIFI-6085 GitHub Pull Request: 3362 If NiFi uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi. NiFi 1.10.0 invalidates the server-side authentication token immediately after the user clicks the Log Out link. Users running a prior release shou
GHSA
Apache NiFi user log out issue
ghsa·2019-12-02
CVE-2019-12421 [HIGH] CWE-613 Apache NiFi user log out issue
Apache NiFi user log out issue
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi.
OSV
Apache NiFi user log out issue
osv·2019-12-02
CVE-2019-12421 [HIGH] Apache NiFi user log out issue
Apache NiFi user log out issue
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2019-12421https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2019-12421
2019-11-19
Published