VendorsApachenifiany version
Vulnerabilities

Apache Software Foundation NiFi any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2020-1933
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
Published 2020-01-28 · Modified
6.1EPSS 0.028
CVE-2018-17193
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Published 2018-12-19 · Modified
6.1EPSS 0.028
CVE-2020-13940
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Published 2020-10-01 · Modified
5.5EPSS 0.019
CVE-2024-37389
Apache NiFi: Improper Neutralization of Input in Parameter Context Description
Published 2024-07-08 · Modified
5.4EPSS 0.240
CVE-2024-56512
Apache NiFi: Missing Complete Authorization for Parameter and Service References
Published 2024-12-28 · Analyzed
5.4EPSS 0.031
CVE-2016-8748
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Published 2017-10-19 · Modified
5.4EPSS 0.020
CVE-2019-10083
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Published 2019-11-19 · Modified
5.3EPSS 0.028
CVE-2017-15703
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Published 2018-01-25 · Modified
5.0EPSS 0.009
CVE-2024-45477
Apache NiFi: Improper Neutralization of Input in Parameter Description
Published 2024-10-29 · Modified
4.6EPSS 0.007
CVE-2022-26850
Insufficiently protected credentials
Published 2022-04-06 · Modified
4.3EPSS 0.015
CVE-2026-81866
Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
Published 2026-09-16 · Analyzed
4.3EPSS 0.006
← Prev2 / 2