PT-2026-93930 · Apache · Apache Nifi
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 2.9.0 through 2.11.0
Description
Connector configuration update and verification REST API methods fail to enforce authorization checks on referenced Assets and Secrets. While framework authorization is limited to write privileges on the Connector, an authenticated user with these privileges could apply Secret values from a Parameter Provider they are not authorized to read. Additionally, these methods accept Asset identifiers without verifying if the Asset belongs to the Connector being configured. This issue affects installations that implement different authorization levels across Connectors and Parameter Providers.
Recommendations
Update to version 2.12.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi