← Back

CVE-2024-37389

nvd nist
Published: Jul 8, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.

Affected (15)

Products: Apache: Nifi
1 product
Nifi
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.10.0 to 1.27.0
Version 2.0.0 milestone1-rc1
Version 2.0.0 milestone1-rc2
Version 2.0.0 milestone1-rc3
Version 2.0.0 milestone1-rc4
Version 2.0.0 milestone1-rc5
Version 2.0.0 milestone1-rc6
Version 2.0.0 milestone1
Version 2.0.0 milestone2-rc1
Version 2.0.0 milestone2-rc2
Version 2.0.0 milestone2-rc3
Version 2.0.0 milestone2-rc4
Version 2.0.0 milestone2
Version 2.0.0 milestone3-rc1
Version 2.0.0 milestone3

References (3)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.