PT-2026-67496 · Apache · Apache Nifi
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 2.0.0 through 2.10.0
Description
Apache NiFi allows the creation, reading, and deletion of Assets associated with Parameter Contexts via the REST API. The framework authorizes asset deletion using the provided Parameter Context Identifier and Asset Identifier but fails to verify the requested Identifier against the stored Identifier. This issue affects installations that implement different levels of authorization across Parameter Contexts; those that do not are not affected as write permissions serve as the security boundary.
Recommendations
Upgrade to Apache NiFi version 2.11.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi