PT-2026-93941 · Apache · Apache Nifi Registry
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache NiFi Registry versions 0.4.0 through 2.11.0
Description
An issue exists during the storage of extension bundle content when using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider uses these coordinates as filesystem path components without rejecting parent-directory names, and the path-containment check utilizes an unnormalized resolved path. This allows an authenticated user with permissions to write and delete bundles in a bucket to upload a NAR with a crafted manifest, enabling file system operations outside of the intended file persistence directory.
Recommendations
Update Apache NiFi Registry to version 2.12.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi Registry