Apache NiFi是美国阿帕奇(Apache)基金会的一套数据处理和分发系统。该系统主要用于数据路由、转换和系统中介逻辑。 Apache NiFi存在安全漏洞,该漏洞源于在为单用户访问创建或更新凭据时,Apache NiFi将登录标识提供程序配置的副本写入操作系统的临时目录。在大多数平台上,操作系统的临时目录具有全局读取权限。Apache NiFi 1.16.0版本包含更新,以替换登录标识提供程序配置,而无需将文件写入操作系统临时目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache NiFi | NiFi 1.14.0 to 1.15.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet