When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2019-11-19T21:34:11
Updated: 2024-08-04T22:10:09.444Z
Reserved: 2019-03-26T00:00:00
Link: CVE-2019-10083
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-11-19T22:15:11.207
Modified: 2024-11-21T04:18:21.883
Link: CVE-2019-10083
Redhat
No data.