Impact
The vulnerability originates from an improper handling of authorization for parameter context validation requests in Apache NiFi versions 1.10.0 through 2.10.0. Users with only read permission can submit proposed parameter values that temporarily override the current configuration, thereby allowing them to invoke predefined component validation methods under alternative settings. This effectively lets read‑only users influence component behavior without having write access, exposing an escalation of privileges that can be used to probe or destabilize the system.
Affected Systems
Affecting the Apache Software Foundation’s Apache NiFi, the flaw is present in all releases from 1.10.0 up to and including 2.10.0. Systems that have distinct authorization levels for viewing and modifying parameter contexts are not impacted, as the required write privilege remains enforced. No other products outside the listed range are known to be vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑severity flaw, but its EPSS score is not provided and it is not listed in the CISA KEV catalog. The likely attack vector is via authenticated API traffic, inferred from the fact that read‑access users can submit validation requests. An attacker with read permissions could exploit this by sending crafted validation queries that alter component behavior temporarily, potentially aiding in further attacks or denial of service.
OpenCVE Enrichment