Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25080
HistoryApr 28, 2020 - 10:16 a.m.

Improper Token Handling

2020-04-2810:16:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.001 Low

EPSS

Percentile

43.9%

Apache NiFi Registry is vulnerable to authentication bypass. During logging out, the authentication mechanism other than PKI does not invalidate the token on the server side, but only on the client side, allowing the client to make a API requests up to 12 hours after logging out.

CPENameOperatorVersion
nifi-registry-web-apile0.5.0

0.001 Low

EPSS

Percentile

43.9%

Related for VERACODE:25080