Description
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, and injecting malicious code into an unprotected (plaintext HTTP) website which the targeted user later visits, but the possible damage warranted a Severe severity level. Mitigation: The fix to apply Cross-Origin Resource Sharing (CORS) policy request filtering was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0794 | The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, and injecting malicious code into an unprotected (plaintext HTTP) website which the targeted user later visits, but the possible damage warranted a Severe severity level. Mitigation: The fix to apply Cross-Origin Resource Sharing (CORS) policy request filtering was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release. |
Github GHSA |
GHSA-3jq8-jg75-rqv6 | Cleartext Transmission of Sensitive Information in Apache nifi |
References
| Link | Providers |
|---|---|
| https://nifi.apache.org/security.html#CVE-2018-17195 |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T10:39:59.593Z
Reserved: 2018-09-19T00:00:00.000Z
Link: CVE-2018-17195
No data.
Status : Modified
Published: 2018-12-19T14:29:00.487
Modified: 2024-11-21T03:54:04.143
Link: CVE-2018-17195
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA