Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7727 | Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record |
Github GHSA |
GHSA-35gq-cvrm-xf94 | Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache nifi |
|
| CPEs | cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache nifi |
|
| Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 12 Mar 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those processors may see the credentials information. Upgrading to Apache NiFi 2.3.0 is the recommended mitigation, which removes the credentials from provenance event records. | |
| Title | Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record | |
| Weaknesses | CWE-538 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-03-12T17:56:14.825Z
Reserved: 2025-02-17T19:27:20.335Z
Link: CVE-2025-27017
Updated: 2025-03-12T17:03:09.415Z
Status : Analyzed
Published: 2025-03-12T17:15:50.327
Modified: 2025-07-16T14:45:49.763
Link: CVE-2025-27017
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA