VulnerabilityModified
CVE-2017-7665
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
MEDIUM 6.1EPSS 3.51%
Does this matter?
Lower severity and a low EPSS score (3.51%). Track it; it rarely justifies an emergency change on its own.
Description
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 3.51% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/nifi
- Source
- security@apache.org
References
- http://www.securityfocus.com/bid/99009Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3E
- http://www.securityfocus.com/bid/99009Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.