📦 Nifi

by Apache

🔍 What is Nifi?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66524

HIGH CVSS 8.8 Dec 19, 2025

This vulnerability allows remote code execution on Apache NiFi systems through unsafe Java deserialization in the GetAsanaObject Processor. Attackers can exploit it by injecting malicious objects into...

CVE-2023-49145

HIGH CVSS 7.9 Nov 27, 2023

This DOM-based cross-site scripting vulnerability in Apache NiFi's JoltTransformJSON Processor allows authenticated users with configuration privileges to execute arbitrary JavaScript by visiting a cr...

CVE-2023-36542

HIGH CVSS 8.8 Jul 29, 2023

This vulnerability allows authenticated and authorized Apache NiFi users to configure HTTP URL references for retrieving drivers, enabling custom code execution. It affects Apache NiFi versions 0.0.2 ...

CVE-2023-22832

HIGH CVSS 7.5 Feb 10, 2023

This vulnerability allows XML External Entity (XXE) attacks in Apache NiFi's ExtractCCDAAttributes Processor. Attackers can exploit this to read arbitrary files from the server or potentially cause de...

CVE-2024-56512

MEDIUM CVSS 5.4 Dec 28, 2024

This vulnerability allows authenticated users with permission to create Process Groups in Apache NiFi to bypass authorization checks for Parameter Contexts, Controller Services, and Parameter Provider...

CVE-2024-52067

MEDIUM CVSS 4.9 Nov 21, 2024

Apache NiFi versions 1.16.0-1.28.0 and 2.0.0-M1-2.0.0-M4 have debug logging that can expose sensitive parameter values when enabled. Authorized administrators can enable debug logging during flow sync...