Known Vulnerabilities for Nifi by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Nifi" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-25903 json | Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that... | Not Provided | 2026-02-17 | 2026-02-17 |
| CVE-2023-49145 json | 5.4 - MEDIUM | 2023-11-27 | 2023-12-01 | |
| CVE-2023-40037 json | Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connect... | 6.5 - MEDIUM | 2023-08-18 | 2023-08-23 |
| CVE-2023-36542 json | Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving d... | 8.8 - HIGH | 2023-07-29 | 2023-08-03 |
| CVE-2023-34468 json | The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authentica... | 8.8 - HIGH | 2023-06-12 | 2023-10-03 |
| CVE-2023-34212 json | The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi ... | 6.5 - MEDIUM | 2023-06-12 | 2023-06-21 |
| CVE-2023-22832 json | The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flo... | 7.5 - HIGH | 2023-02-10 | 2023-11-07 |
| CVE-2022-33140 json | The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutral... | 8.8 - HIGH | 2022-06-15 | 2022-06-23 |
| CVE-2022-29265 json | Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuratio... | 7.5 - HIGH | 2022-04-30 | 2022-05-10 |
| CVE-2022-26850 json | When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers config... | 4.3 - MEDIUM | 2022-04-06 | 2023-08-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.1 | |||
| Application | Apache | Nifi | 1.9.1 | |||
| Application | Apache | Nifi | 1.9.0 | |||
| Application | Apache | Nifi | 1.9.0 | |||
| Application | Apache | Nifi | 1.9.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.7.1 | |||
| Application | Apache | Nifi | 1.7.1 | |||
| Application | Apache | Nifi | 1.7.1 | |||
| Application | Apache | Nifi | 1.7.0 | |||
| Application | Apache | Nifi | 1.7.0 | |||
| Application | Apache | Nifi | 1.7.0 |