Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nifi | Apache | * | 0.7.3 (including) |
Nifi | Apache | 1.0.0 (including) | 1.0.0 (including) |
Nifi | Apache | 1.0.1 (including) | 1.0.1 (including) |
Nifi | Apache | 1.1.0 (including) | 1.1.0 (including) |
Nifi | Apache | 1.1.1 (including) | 1.1.1 (including) |
Nifi | Apache | 1.1.2 (including) | 1.1.2 (including) |
Nifi | Apache | 1.2.0 (including) | 1.2.0 (including) |