[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] [CVE-2020-1933] Apache NiFi XSS Attack
From:       Nathan Gough <thenatog () apache ! org>
Date:       2020-01-27 17:08:03
Message-ID: CAEhjM2ByDcfuf-mGxZBjjqqD+brvH6sFHTEt--MMsqB3W8iUOQ () mail ! gmail ! com
[Download RAW message or body]


[CVEID]:CVE-2020-1933

[PRODUCT]:Apache NiFi

[VERSION]:Apache NiFi 1.0.0 to 1.10.0

[PROBLEMTYPE]:XSS Attack

[REFERENCES]:https://nifi.apache.org/security.html#CVE-2020-1933

[DESCRIPTION]:As reported by Jakub Palaczynski (ING Tech Poland), malicious
scripts could be injected to the UI through action by an unaware
authenticated user in Firefox. Did not appear to occur in other browsers.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic