← Back

CVE-2017-5635

nvd nist
Published: Oct 19, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.

Affected (4)

Products: Apache: Nifi
1 product
Nifi
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 0.7.0
Version 0.7.1
Version 1.1.0
Version 1.1.1

References (4)

Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory

Timeline

No history available yet.