Impact
This vulnerability allows an authenticated attacker with access to the NiFi REST API to delete assets from a Parameter Context without properly verifying ownership. The framework authorizes deletion based solely on the supplied Parameter Context Identifier, ignoring the requested Asset Identifier, which can lead to the removal of assets belonging to other contexts and compromise asset integrity.
Affected Systems
NiFi installations running versions 2.0.0 through 2.10.0 are affected, unless the deployment enforces separate authorization levels for each Parameter Context. The flaw resides in the asset deletion endpoint of the REST API when write permissions are granted for parameter contexts.
Risk and Exploitability
The vulnerability scores a CVSS of 2.3, indicating low severity, and has no EPSS score available. It is not listed in the CISA KEV catalog. The likely attack vector is via the REST API, which may be exposed locally or remotely; however, the exploitation probability is low and no public exploits are known.
OpenCVE Enrichment