Impact
The vulnerability allows authenticated users with permission to write and delete bundles to cause file system operations outside the designated persistence directory by uploading a NAR bundle with a crafted manifest. This path manipulation results from the path‑containment check using an unnormalised resolved path and permitting parent‑directory names in the group, artifact, and version coordinates. Because the bad path is accepted, an attacker can write, overwrite, or delete arbitrary files on the host filesystem, potentially affecting critical system or application files.
Affected Systems
Apache NiFi Registry versions 0.4.0 through 2.11.0 are affected. The product is the Apache NiFi Registry component of the Apache Software Foundation’s NiFi suite. Upgrading to version 2.12.0 or later provides the fix that rejects parent‑directory coordinates and enforces normalization of the storage path.
Risk and Exploitability
The severity is assessed with a CVSS score of 7.2, indicating a high impact. The EPSS score is below 1 %, implying that the probability of exploitation is low at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires valid credentials with write/delete rights to a bucket and the ability to upload an extension bundle. The attack path is local and authenticated, with filesystem access and the ability to manipulate storage paths.
OpenCVE Enrichment