{"api_version":"1","generated_at":"2026-07-23T08:57:17+00:00","cve":"CVE-2019-10083","urls":{"html":"https://cve.report/CVE-2019-10083","api":"https://cve.report/api/cve/CVE-2019-10083.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10083","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10083"},"summary":{"title":"CVE-2019-10083","description":"When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.","state":"PUBLIC","assigner":"security@apache.org","published_at":"2019-11-19 22:15:00","updated_at":"2023-11-07 03:02:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://nifi.apache.org/security.html#CVE-2019-10083","name":"https://nifi.apache.org/security.html#CVE-2019-10083","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Apache NiFi Security Reports","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","name":"[nifi-commits] 20200123 svn commit: r1873083 - /nifi/site/trunk/security.html","refsource":"MLIST","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","name":"[nifi-commits] 20200123 svn commit: r1873083 - /nifi/site/trunk/security.html","refsource":"","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10083","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10083","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10083","vulnerable":"1","versionEndIncluding":"1.9.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"nifi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10083","qid":"981615","title":"Java (maven) Security Update for org.apache.nifi:nifi (GHSA-26p8-xrj2-mv53)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10083","ASSIGNER":"security@apache.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Apache NiFi","version":{"version_data":[{"version_value":"Apache NiFi 1.3.0 to 1.9.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Disclosure"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://nifi.apache.org/security.html#CVE-2019-10083","url":"https://nifi.apache.org/security.html#CVE-2019-10083"},{"refsource":"MLIST","name":"[nifi-commits] 20200123 svn commit: r1873083 - /nifi/site/trunk/security.html","url":"https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E"}]},"description":{"description_data":[{"lang":"eng","value":"When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to."}]}},"nvd":{"publishedDate":"2019-11-19 22:15:00","lastModifiedDate":"2023-11-07 03:02:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*","versionStartIncluding":"1.3.0","versionEndIncluding":"1.9.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10083","Ordinal":"148297","Title":"CVE-2019-10083","CVE":"CVE-2019-10083","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10083","Ordinal":"1","NoteData":"When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10083","Ordinal":"2","NoteData":"2019-11-19","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10083","Ordinal":"3","NoteData":"2020-01-23","Type":"Other","Title":"Modified"}]}}}