Lucene search

K
osvGoogleOSV:GHSA-W4FJ-CCR6-7PCP
HistoryJan 06, 2022 - 8:40 p.m.

Apache NiFi Insertion of Sensitive Information into Log File

2022-01-0620:40:56
Google
osv.dev
5

5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.7%

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.

CPENameOperatorVersion
org.apache.nifi:nifi-parametereq1.10.0

5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.7%

Related for OSV:GHSA-W4FJ-CCR6-7PCP