Vulnerability identifier: #VU101976
Vulnerability risk: Low
CVSSv4.0: 2.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear]
CVE-ID: CVE-2024-56512
CWE-ID:
CWE-862
Exploitation vector: Network
Exploit availability: Yes
Vulnerable software:
Apache Nifi
Server applications /
Database software
Vendor: Apache Foundation
Description
The vulnerability allows a remote user to bypass certain security restrictions.
The vulnerability exists due to missing authorization checks for parameters context when creating process groups. A remote authenticated user with privileges to create process groups can bypass authorization checks by not referencing parameter values and gain access to sensitive information.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Apache Nifi: 1.10.0 - 2.0.0
External links
https://lists.apache.org/thread/skjxd4899mhvytq9lpvrlwhprt09c2dd
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.