QID 981401
QID 981401: Java (maven) Security Update for org.apache.nifi:nifi (GHSA-2xpp-75vr-22vq)
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2xpp-75vr-22vq for updates pertaining to this vulnerability.
Vendor References
- GHSA-2xpp-75vr-22vq -
github.com/advisories/GHSA-2xpp-75vr-22vq
CVEs related to QID 981401
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2xpp-75vr-22vq | org.apache.nifi:nifi |
|