Impact
Apache NiFi’s REST API for updating or verifying connector configurations fails to enforce read‑level authorization on referenced assets and secrets. An authenticated user with write privilege on a connector can supply references to any parameter provider or asset, causing the framework to store or apply secret values that the user would normally be barred from reading. The lack of ownership checks on assets allows an attacker to attach arbitrary assets to a connector without permission. This flaw permits non‑privileged users to gain access to protected secrets and asset data, potentially exposing sensitive configuration information.
Affected Systems
Apache NiFi versions 2.9.0 through 2.11.0 are affected. All installations without separate authorization levels for connectors and parameter providers are vulnerable. Upgrading beyond 2.11.0 removes the issue.
Risk and Exploitability
The CVSS score of 0.5 indicates a low‑impact vulnerability. The EPSS of less than 1% reflects a very low probability that exploitation will occur. Because the flaw requires an authenticated user with connector write rights, the practical exploitation window is narrow. The vulnerability is not currently listed in CISA’s KEV catalog. Still, an attacker may use the flaw to exfiltrate secrets from the system.
OpenCVE Enrichment