Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-mpj7-7mg7-x95j] Apache NiFi: Missing Complete Authorization for Parameter and Service References #5146

Conversation

exceptionfactory
Copy link

Updates

  • Affected products
  • CVSS v4

Comments
The additional modules listed include nifi-client-dto, which is a collection of model objects, nifi-system-test-suite, which contains a set of integration tests, and other framework modules that are not involved in the authorization process. The affected products should be limited to nifi-web-api as published in the initial release of the vulnerability and visible in the CVE Record JSON.

@exceptionfactory
Copy link
Author

Please note that removing /U:Green from the CVSS vector was not intentional, but required for form validation in the improvement submission, so that change can be reverted.

@github-actions github-actions bot changed the base branch from main to exceptionfactory/advisory-improvement-5146 January 6, 2025 16:33
@advisory-database advisory-database bot merged commit 81fe1e2 into exceptionfactory/advisory-improvement-5146 Jan 6, 2025
2 checks passed
@advisory-database
Copy link
Contributor

Hi @exceptionfactory! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the exceptionfactory-GHSA-mpj7-7mg7-x95j branch January 6, 2025 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant