PT-2025-52439 · Apache · Nifi-Asana-Processors-Nar+2

·

CVE-2025-66524

·

Published

2025-12-19

·

Updated

2026-01-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.20.0 through 2.6.0
Description The GetAsanaObject Processor in Apache NiFi utilizes a Distribute Map Cache Client Service for state management. This processor employs Java Object serialization and deserialization without adequate filtering, creating a potential for exploitation through crafted state information stored in the cache server. Successful exploitation requires access to the configured cache server and an Apache NiFi system running the GetAsanaObject Processor.
Recommendations Upgrade to Apache NiFi version 2.7.0, which replaces Java Object serialization with JSON serialization. Remove the GetAsanaObject Processor located in the nifi-asana-processors-nar bundle.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2025-66524
CVE-2025-66524
GHSA-V4P2-2W39-MHRJ

Affected Products

Apache Nifi
Getasanaobject Processor
Nifi-Asana-Processors-Nar