GHSA-7q8g-gpfp-v8gx
Dashboard / Vulnerabilities / GHSA-7q8g-gpfp-v8gx
GHSA-7q8g-gpfp-v8gx
Summary: Insertion of Sensitive Information into Log File in Apache NiFi
Details: In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-1942, https://github.com/apache/nifi/pull/4028, https://github.com/apache/nifi/commit/95746d346cddbd6134c4b28fdc39d5813a626f97, https://github.com/apache/nifi/commit/d7c29f46378379fb596e4d1e59d1a3c41063db5b, https://issues.apache.org/jira/browse/NIFI-7079, https://nifi.apache.org/security.html#CVE-2020-1942
Affected packages
Package
Name: org.apache.nifi:nifi-framework-core
Purl: pkg:maven/org.apache.nifi/nifi-framework-core
Affected ranges
Type: ECOSYSTEM
Events:
