CVE-2024-52067
published 2024-11-21CVE-2024-52067: Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.74%
50.2th percentile
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on application flow configuration. Deployments of Apache NiFi with the default Logback configuration do not log Parameter Context values. Upgrading to Apache NiFi 2.0.0 or 1.28.1 is the recommendation mitigation, eliminating Parameter value logging from the flow synchronization process regardless of the Logback configuration.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | — | — |
| apache | nifi | >= 1.16.0 < 1.28.1 | 1.28.1 |
| apache_software_foundation | apache_nifi | 1.16.0 – 1.28.0 | — |
| apache_software_foundation | apache_nifi | 2.0.0-M1 – 2.0.0-M4 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Green
vendor_apache6.9
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2024-52067
vendor_apache·CVSS 6.9
CVE-2024-52067 Apache nifi: CVE-2024-52067
Apache nifi: CVE-2024-52067
Title: Potential Insertion of Sensitive Parameter Values in Debug Log Published: 2024-11-20 Severity: Medium Products: Apache NiFi Affected Versions: 1.16.0 to 1.28.0 and 2.0.0-M1 to 2.0.0-M4 Fixed Versions: 1.28.1 and 2.0.0 Reporter: David Handermann References CVE Record: CVE-2024-52067 NVD Record: CVE-2024-52067 Apache Jira Issue: NIFI-13971 GitHub Pull Request: 9489 Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context value
GHSA
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
ghsa·2025-02-11
CVE-2024-52067 [MEDIUM] CWE-532 Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on application flow configuration. Deployments of Apache NiFi with the default Logback configuration do not log Parameter Context values. Upgrading to Apache NiFi 2.0.0 or 1.28.1 is the recommendation mitigation, eliminating Parameter value logging from the flow synchronization
OSV
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
osv·2025-02-11
CVE-2024-52067 [MEDIUM] Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on application flow configuration. Deployments of Apache NiFi with the default Logback configuration do not log Parameter Context values. Upgrading to Apache NiFi 2.0.0 or 1.28.1 is the recommendation mitigation, eliminating Parameter value logging from the flow synchronization
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-21
Published