Missing Authorization in Apache Nifi - CVE-2024-56512

 

Missing Authorization in Apache Nifi - CVE-2024-56512

Published: December 28, 2024 / Updated: January 10, 2025


Vulnerability identifier: #VU101976
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-56512
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to bypass certain security restrictions.

The vulnerability exists due to missing authorization checks for parameters context when creating process groups. A remote authenticated user with privileges to create process groups can bypass authorization checks by not referencing parameter values and gain access to sensitive information.


Affected software

Apache Nifi

How to mitigate CVE-2024-56512

Install updates from vendor's website.

Apache Nifi - update to 2.1.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins