Impact
The vulnerability arises from missing authorization checks when replacing the contents of a Process Group via the REST API. This flaw, based on CWE‑862, permits an authenticated user who has write permission on a Process Group to upload a new flow definition that modifies or removes components in nested Process Groups guarded by stricter access policies, or to bind components to Controller Services and Parameter Contexts without the proper authorizations. As a result, the attacker can introduce unauthorized configuration changes that may disrupt services or expose sensitive interactions. Existing verification checks limit the impact to stopped components, but the potential for configuration manipulation remains significant.
Affected Systems
Apache NiFi versions 1.5.0 through 2.11.0 are affected by this issue. The flaw is only present in deployments that enable component‑level authorization policies; systems that rely solely on Process Group level permissions are not impacted. The recommended fix is to upgrade to NiFi 2.12.0 or later, which enforces consistent reference resolution and component authorization for all flow update methods.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker would need to be authenticated with write access to a Process Group, a scenario that typically indicates internal or compromised credentials. Given the limited exploitation window and the requirement for existing component‑level security, the overall risk is moderate but still actionable.
OpenCVE Enrichment