Cross-site Scripting in Apache NiFi
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Package
Affected versions
< 1.0.1
>= 1.1.0, < 1.1.1
Patched versions
1.0.1
1.1.1
Description
Published by the National Vulnerability Database
Oct 19, 2017
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Nov 1, 2022
Last updated
Jan 30, 2023
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
References