QID 981319
QID 981319: Java (maven) Security Update for org.apache.nifi:nifi (GHSA-4qq9-rrq6-48ff)
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4qq9-rrq6-48ff for updates pertaining to this vulnerability.
Vendor References
- GHSA-4qq9-rrq6-48ff -
github.com/advisories/GHSA-4qq9-rrq6-48ff
CVEs related to QID 981319
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4qq9-rrq6-48ff | org.apache.nifi:nifi |
|