In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2020-02-11T20:57:26

Updated: 2024-08-04T06:54:00.412Z

Reserved: 2019-12-02T00:00:00

Link: CVE-2020-1942

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-02-11T21:15:11.113

Modified: 2021-07-21T11:39:23.747

Link: CVE-2020-1942

cve-icon Redhat

No data.