PT-2024-31656 · Apache · Apache Nifi

·

CVE-2024-45477

·

Published

2024-10-29

·

Updated

2026-09-04

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: Apache NiFi versions 1.10.0 through 1.27.0 Apache NiFi versions 2.0.0-M1 through 2.0.0-M3
Description: The vulnerability allows an authenticated user, authorized to configure a Parameter Context, to enter arbitrary JavaScript code in the description field for Parameters. This code will be executed by the client browser within the session context of the authenticated user, enabling cross-site scripting attacks.
Recommendations: For Apache NiFi versions 1.10.0 through 1.27.0, upgrade to Apache NiFi 1.28.0. For Apache NiFi versions 2.0.0-M1 through 2.0.0-M3, upgrade to Apache NiFi 2.0.0-M4.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2024-45477
CVE-2024-45477
GHSA-7MQJ-XGF8-P59V

Affected Products

Apache Nifi