Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44463
HistoryNov 29, 2023 - 7:40 a.m.

Cross Site Scripting (XSS)

2023-11-2907:40:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2
apache nifi
cross site scripting
xss vulnerability
user input
sanitization
malicious url
javascript
session context
authenticated user
software

7.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.5%

Apache NiFi is vulnerable to Cross Site Scripting (XSS). The vulnerability is due to improper sanitization of user input. This issue can be exploited by an attacker via crafting specific malicious url to execute Javascript within the session context of the authenticated user.

7.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.5%

Related for VERACODE:44463