GHSA-3pp3-77j6-8ph6
Dashboard / Vulnerabilities / GHSA-3pp3-77j6-8ph6
GHSA-3pp3-77j6-8ph6
Summary: Missing Authentication for Critical Function in Apache NiFi
Details: In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly request download tokens, preventing legitimate users from requesting download tokens.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-9487, https://github.com/apache/nifi/commit/01e42dfb3291c3a3549023edadafd2d8023f3042, https://nifi.apache.org/security#CVE-2020-9487
Affected packages
Package
Name: org.apache.nifi:nifi
Purl: pkg:maven/org.apache.nifi/nifi
Affected ranges
Type: ECOSYSTEM
Events:
