Description
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0596 | In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext. |
Github GHSA |
GHSA-g644-pr5v-vppf | Insertion of Sensitive Information into Log File in Apache NiFi Stateless |
References
| Link | Providers |
|---|---|
| https://nifi.apache.org/security#CVE-2020-9486 |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T10:26:16.358Z
Reserved: 2020-03-01T00:00:00.000Z
Link: CVE-2020-9486
No data.
Status : Modified
Published: 2020-10-01T20:15:14.190
Modified: 2024-11-21T05:40:44.833
Link: CVE-2020-9486
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA