When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2019-0770 | When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to. |
![]() |
GHSA-26p8-xrj2-mv53 | Apache NiFi process group information disclosure |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T22:10:09.444Z
Reserved: 2019-03-26T00:00:00
Link: CVE-2019-10083

No data.

Status : Modified
Published: 2019-11-19T22:15:11.207
Modified: 2024-11-21T04:18:21.883
Link: CVE-2019-10083

No data.

No data.