CVE-2024-37389
published 2024-07-08CVE-2024-37389: Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to…
PriorityP337medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
24.03%
97.6th percentile
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | >= 1.10.0 < 1.27.0 | 1.27.0 |
| apache_software_foundation | apache_nifi | 1.10.0 – 1.26.0 | — |
| apache_software_foundation | apache_nifi | 2.0.0-M1 – 2.0.0-M3 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_apache4.6
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache NiFi vulnerable to Cross-site Scripting
ghsa·2024-07-08
CVE-2024-37389 [MEDIUM] CWE-79 Apache NiFi vulnerable to Cross-site Scripting
Apache NiFi vulnerable to Cross-site Scripting
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.
OSV
Apache NiFi vulnerable to Cross-site Scripting
osv·2024-07-08
CVE-2024-37389 [MEDIUM] Apache NiFi vulnerable to Cross-site Scripting
Apache NiFi vulnerable to Cross-site Scripting
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.
Apache
Apache nifi: CVE-2024-37389
vendor_apache·CVSS 4.6
CVE-2024-37389 Apache nifi: CVE-2024-37389
Apache nifi: CVE-2024-37389
Title: Improper Neutralization of Input in Parameter Context Description Published: 2024-07-08 Severity: Medium Products: Apache NiFi Affected Versions: 1.10.0 to 1.26.0 and 2.0.0-M1 to 2.0.0-M3 Fixed Versions: 1.27.0 and 2.0.0-M4 Reporter: Akbar Kustirama at abay.sh, GitHub user abaykan References CVE Record: CVE-2024-37389 NVD Record: CVE-2024-37389 Apache Jira Issue: NIFI-13374 GitHub Pull Request: 8938 Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authentica
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-08
Published