CVE-2020-9491
published 2020-10-01CVE-2020-9491: In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.87%
85.2th percentile
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.0.0 – 1.11.4 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2020-9491
vendor_apache·CVSS 7.5
CVE-2020-9491 [HIGH] Apache nifi: CVE-2020-9491
Apache nifi: CVE-2020-9491
Title: Insecure TLS Protocol Versions for Cluster Communication Published: 2020-08-18 Severity: High Products: Apache NiFi Affected Versions: 1.2.0 to 1.11.4 Fixed Versions: 1.12.0 Reporter: Juan Carlos Sequeiros and Andy LoPresto References CVE Record: CVE-2020-9491 NVD Record: CVE-2020-9491 Apache Jira Issue: NIFI-7407 GitHub Pull Request: 4263 The NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP and HandleHttpRequest. However intra-cluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS 1.0 or 1.1. NiFI 1.12.0 refactored disparate internal SSL and TLS code, reducing exposure for extension and framework developers to
GHSA
Inadequate Encryption Strength in Apache NiFi
ghsa·2022-01-06
CVE-2020-9491 [HIGH] CWE-327 Inadequate Encryption Strength in Apache NiFi
Inadequate Encryption Strength in Apache NiFi
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.
OSV
Inadequate Encryption Strength in Apache NiFi
osv·2022-01-06
CVE-2020-9491 [HIGH] Inadequate Encryption Strength in Apache NiFi
Inadequate Encryption Strength in Apache NiFi
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r2d9c21f9ec35d66f2bb42f8abe876dabd786166b6284e9a33582c718%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/re48582efe2ac973f8cff55c8b346825cb491c71935e15ab2d61ef3bf%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security#CVE-2020-9491https://lists.apache.org/thread.html/r2d9c21f9ec35d66f2bb42f8abe876dabd786166b6284e9a33582c718%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/re48582efe2ac973f8cff55c8b346825cb491c71935e15ab2d61ef3bf%40%3Ccommits.nifi.apache.org%3Ehttps://nifi.apache.org/security#CVE-2020-9491
2020-10-01
Published