Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2356 | Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation. |
Github GHSA |
GHSA-h658-qqv9-qwv8 | Apache NiFi vulnerable to Cross-site Scripting |
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:04:52.641Z
Reserved: 2024-06-07T21:09:31.675Z
Link: CVE-2024-37389
Updated: 2024-09-13T17:04:52.641Z
Status : Modified
Published: 2024-07-08T08:15:10.847
Modified: 2024-11-21T09:23:46.127
Link: CVE-2024-37389
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA