CVE-2024-45477
published 2024-10-29CVE-2024-45477: Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is…
PriorityP423medium4.6CVSS 3.1
AVNACLPRLUIRSUCLILAN
EPSS
0.65%
46.7th percentile
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.28.0 or 2.0.0-M4 is the recommended mitigation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | 1.10.0 – 1.27.0 | — |
| apache_software_foundation | apache_nifi | 1.10.0 – 1.27.0 | — |
| apache_software_foundation | apache_nifi | 2.0.0-M1 – 2.0.0-M3 | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
vendor_apache4.6
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache NiFi Cross-site Scripting vulnerability
osv·2024-10-29
CVE-2024-45477 [MEDIUM] Apache NiFi Cross-site Scripting vulnerability
Apache NiFi Cross-site Scripting vulnerability
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.28.0 or 2.0.0-M4 is the recommended mitigation.
GHSA
Apache NiFi Cross-site Scripting vulnerability
ghsa·2024-10-29
CVE-2024-45477 [MEDIUM] CWE-79 Apache NiFi Cross-site Scripting vulnerability
Apache NiFi Cross-site Scripting vulnerability
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.28.0 or 2.0.0-M4 is the recommended mitigation.
Apache
Apache nifi: CVE-2024-45477
vendor_apache·CVSS 4.6
CVE-2024-45477 Apache nifi: CVE-2024-45477
Apache nifi: CVE-2024-45477
Title: Improper Neutralization of Input in Parameter Description Published: 2024-10-28 Severity: Medium Products: Apache NiFi Affected Versions: 1.10.0 to 1.27.0 and 2.0.0-M1 to 2.0.0-M3 Fixed Versions: 1.28.0 and 2.0.0-M4 Reporter: Muhammad Hazim Bin Nor Aizi References CVE Record: CVE-2024-45477 NVD Record: CVE-2024-45477 Apache Jira Issue: NIFI-13675 GitHub Pull Request: 9195 Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgra
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-29
Published