Impact
Apache NiFi exposes a flaw in its migration API where the request to list or migrate a version‑controlled Process Group is authorized only against the target Connector, ignoring the user’s permissions on the source Process Group. An authenticated user who merely has read rights to a Connector can learn the identifiers, names, and flow registry details of all version‑controlled Process Groups, including those outside the user’s read scope. A user with write rights to the Connector can even migrate a Process Group without having write permissions on that Process Group, effectively copying the flow definition, referenced assets, and component state into the Connector while disabling and renaming the source. The migration skips sensitive property values and requires the source to be stopped with empty queues, limiting but not eliminating exposure.
Affected Systems
Vulnerable instances are Apache NiFi 2.11.0 installations or earlier that lack component‑level authorization policies for Process Groups. Installing Apache NiFi 2.12.0 or later mitigates the issue by filtering migration sources to those Process Groups the requesting user is authorized to read and by requiring write access to the source Process Group for migration operations.
Risk and Exploitability
The CVSS score of 2.3 indicates a low overall risk, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and possess at least Connector read or write rights; the attack vector is therefore limited to legitimate users who lack proper Process Group permissions.
OpenCVE Enrichment