CVE-2020-1942
published 2020-02-11CVE-2020-1942: In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.12%
86.3th percentile
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 0.0.1 – 1.11.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insertion of Sensitive Information into Log File in Apache NiFi
osv·2022-01-06
CVE-2020-1942 [HIGH] Insertion of Sensitive Information into Log File in Apache NiFi
Insertion of Sensitive Information into Log File in Apache NiFi
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
GHSA
Insertion of Sensitive Information into Log File in Apache NiFi
ghsa·2022-01-06
CVE-2020-1942 [HIGH] CWE-200 Insertion of Sensitive Information into Log File in Apache NiFi
Insertion of Sensitive Information into Log File in Apache NiFi
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
Apache
Apache nifi: CVE-2020-1942
vendor_apache·CVSS 7.5
CVE-2020-1942 Apache nifi: CVE-2020-1942
Apache nifi: CVE-2020-1942
Title: Potential Information Disclosure in Application Logs Published: 2020-02-04 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.1 to 1.11.0 Fixed Versions: 1.11.1 Reporter: Andy LoPresto References CVE Record: CVE-2020-1942 NVD Record: CVE-2020-1942 Apache Jira Issue: NIFI-7079 GitHub Pull Request: 4208 The flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext. NiFi 1.11.1i implemented Argon2 secure hashing to provide a deterministic loggable value which does not reveal the sensitive valu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-11
Published