GHSA-43fp-vwwg-qgv6

    Dashboard / Vulnerabilities / GHSA-43fp-vwwg-qgv6

    GHSA-43fp-vwwg-qgv6

    Published: 20 Dec 2018Last Modified: 4 Mar 2024

    Summary: Apache NiFi Improper Input Validation vulnerability

    Details: When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait for the body and eventually timeout. Mitigation: The fix to check DELETE requests and overwrite non-zero Content-Length header values was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Affected packages

    Package

    Name: org.apache.nifi:nifi-framework-cluster

    Purl: pkg:maven/org.apache.nifi/nifi-framework-cluster

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.0.0
    Fixed -1.8.0

    Affected versions

    1.0.0
    1.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High