PT-2026-93932 · Apache · Apache Nifi
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi version 2.11.0
Description
An authorization flaw exists in the REST API methods used to list migration sources and submit migration requests when moving version-controlled Process Group contents into a Connector. The system only verified permissions for the target Connector, failing to evaluate access rights for the involved Process Groups. This allows an authenticated user with read access to a Connector to enumerate identifiers, names, and flow registry details of Process Groups they are not authorized to read. Additionally, a user with write access to a Connector can migrate a Process Group they do not have write access to, which copies the flow definition, referenced assets, and component state into the Connector while disabling and renaming the source Process Group. This issue does not affect installations that do not use component-level authorization policies for Process Groups. The migration process requires the source Process Group to be stopped with empty queues and does not include sensitive property values.
Recommendations
Upgrade to version 2.12.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi