← Back

CVE-2024-45477

nvd nist
Published: Oct 29, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.5
Source: NVD

Description

Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.28.0 or 2.0.0-M4 is the recommended mitigation.

Affected (4)

Products: Apache: Nifi
1 product
Nifi
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.10.0 to 1.27.0
Version 2.0.0 milestone1
Version 2.0.0 milestone2
Version 2.0.0 milestone3

References (2)

Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.