CVE-2020-1928
published 2020-01-28CVE-2020-1928: An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
3.96%
89.2th percentile
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache5.3
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2020-1928
vendor_apache·CVSS 5.3
CVE-2020-1928 Apache nifi: CVE-2020-1928
Apache nifi: CVE-2020-1928
Title: Potential Information Disclosure in Application Debug Logs Published: 2020-01-22 Severity: Medium Products: Apache NiFi Affected Versions: 1.10.0 Fixed Versions: 1.11.0 Reporter: Andy LoPresto References CVE Record: CVE-2020-1928 NVD Record: CVE-2020-1928 Apache Jira Issue: NIFI-6948 GitHub Pull Request: 3935 The sensitive parameter parser would log parsed property descriptor values for debugging purposes. This would expose literal values entered a sensitive property when no parameter was present. NiFi 1.11.0 removed debug logging from the class. Users running the 1.10.0 release should upgrade to 1.11.0.
Severity: moderate
OSV
Apache NiFi Insertion of Sensitive Information into Log File
osv·2022-01-06
CVE-2020-1928 [MEDIUM] Apache NiFi Insertion of Sensitive Information into Log File
Apache NiFi Insertion of Sensitive Information into Log File
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
GHSA
Apache NiFi Insertion of Sensitive Information into Log File
ghsa·2022-01-06
CVE-2020-1928 [MEDIUM] CWE-200 Apache NiFi Insertion of Sensitive Information into Log File
Apache NiFi Insertion of Sensitive Information into Log File
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2020-1928https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3Ehttps://nifi.apache.org/security.html#CVE-2020-1928
2020-01-28
Published