CVE Vulnerabilities

CVE-2017-5635

Improper Authentication

Published: Oct 19, 2017 | Modified: Oct 03, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the anonymous user.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Nifi Apache 0.7.0 (including) 0.7.0 (including)
Nifi Apache 0.7.1 (including) 0.7.1 (including)
Nifi Apache 1.1.0 (including) 1.1.0 (including)
Nifi Apache 1.1.1 (including) 1.1.1 (including)

Potential Mitigations

References