When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2019-11-19 22:15
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10083
Mitre link : CVE-2019-10083
CVE.ORG link : CVE-2019-10083
JSON object : View
Products Affected
                apache
- nifi
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
