CVE-2020-1933
published 2020-01-28CVE-2020-1933: A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.81%
84.9th percentile
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.0.0 – 1.10.0 | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_apache6.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2020-1933
vendor_apache·CVSS 6.1
CVE-2020-1933 Apache nifi: CVE-2020-1933
Apache nifi: CVE-2020-1933
Title: Potential Cross-Site Scripting in Uploaded Templates Published: 2020-01-22 Severity: Medium Products: Apache NiFi Affected Versions: 1.0.0 to 1.10.0 Fixed Versions: 1.11.0 Reporter: Jakub Palaczynski of ING Tech Poland References CVE Record: CVE-2020-1933 NVD Record: CVE-2020-1933 Apache Jira Issue: NIFI-7023 GitHub Pull Request: 3991 Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers. NiFi 1.11.0 adds sanitization of the error response ensures the XSS would not be executed. Users running earlier versions should upgrade to 1.11.0.
Severity: moderate
OSV
Cross-site scripting in Apache NiFi
osv·2022-01-06
CVE-2020-1933 [MEDIUM] Cross-site scripting in Apache NiFi
Cross-site scripting in Apache NiFi
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
GHSA
Cross-site scripting in Apache NiFi
ghsa·2022-01-06
CVE-2020-1933 [MEDIUM] CWE-79 Cross-site scripting in Apache NiFi
Cross-site scripting in Apache NiFi
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-28
Published