CVE-2020-9486
published 2020-10-01CVE-2020-9486: In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.56%
88.0th percentile
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.0.0 – 1.11.4 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Insertion of Sensitive Information into Log File in Apache NiFi Stateless
ghsa·2022-01-06
CVE-2020-9486 [HIGH] CWE-532 Insertion of Sensitive Information into Log File in Apache NiFi Stateless
Insertion of Sensitive Information into Log File in Apache NiFi Stateless
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.
OSV
Insertion of Sensitive Information into Log File in Apache NiFi Stateless
osv·2022-01-06
CVE-2020-9486 [HIGH] Insertion of Sensitive Information into Log File in Apache NiFi Stateless
Insertion of Sensitive Information into Log File in Apache NiFi Stateless
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.
Apache
Apache nifi: CVE-2020-9486
vendor_apache·CVSS 7.5
CVE-2020-9486 Apache nifi: CVE-2020-9486
Apache nifi: CVE-2020-9486
Title: Potential Information Disclosure in Application Logs Published: 2020-08-18 Severity: Medium Products: Apache NiFi Affected Versions: 1.10.0 to 1.11.4 Fixed Versions: 1.12.0 Reporter: Andy LoPresto and Pierre Villard References CVE Record: CVE-2020-9486 NVD Record: CVE-2020-9486 Apache Jira Issue: NIFI-7377 GitHub Pull Request: 4222 The NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext. NiFi 1.12.0 implemented Argon2 secure hashing to provide a deterministic loggable value which does not reveal the sensitive value. Users running any previous NiFi release should upgrade to 1.12.0.
Seve
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-01
Published