Skip to main content

Vendor/product archive

apache / nifi CVEs

Beta · best-effort

50 CVEs tagged to apache / nifi3 Critical, 23 High, 22 Medium, 2 Low, 0 Unrated.

CVE-2026-54665

Published Jun 22, 2026

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44914

Published Jun 22, 2026

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restrict…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44913

Published Jun 22, 2026

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming.…

CVSS 5.2 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44911

Published Jun 22, 2026

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration prope…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-39816

Published May 8, 2026

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The T…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-25903

Published Feb 17, 2026

Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restr…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-66524

Published Dec 19, 2025

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrievin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27017

Published Mar 12, 2025

Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during process…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-56512

Published Dec 28, 2024

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52067

Published Nov 21, 2024

Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized a…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45477

Published Oct 29, 2024

Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site sc…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37389

Published Jul 8, 2024

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49145

Published Nov 27, 2023

Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site script…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40037

Published Aug 18, 2023

Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient pr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36542

Published Jul 29, 2023

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34468

Published Jun 12, 2023

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL wi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
21.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-34212

Published Jun 12, 2023

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and author…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22832

Published Feb 10, 2023

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttribut…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29265

Published Apr 30, 2022

Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to res…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26850

Published Apr 6, 2022

When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. O…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44145

Published Dec 17, 2021

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sen…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20190

Published Jan 19, 2021

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is…

CVSS 8.1 · High
evidence mentions
6
Buzz score
35.5

CVE-2020-9491

Published Oct 1, 2020

In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpReq…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2