← Back

CVE-2020-1933

nvd nist
Published: Jan 28, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.

Affected (1)

Products: Apache: Nifi
1 product
Nifi
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.10.0
Running on/withPlatform Versions
Mozilla
Firefox
All versions

References (2)

Source: security@apache.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.