QID 981333
QID 981333: Java (maven) Security Update for org.apache.nifi:nifi (GHSA-43fp-vwwg-qgv6)
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait for the body and eventually timeout. Mitigation: The fix to check DELETE requests and overwrite non-zero Content-Length header values was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-43fp-vwwg-qgv6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-43fp-vwwg-qgv6 -
github.com/advisories/GHSA-43fp-vwwg-qgv6
CVEs related to QID 981333
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-43fp-vwwg-qgv6 | org.apache.nifi:nifi |
|