Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
Vulnerability Description
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the service prior to submitting the query. The missing Restricted annotation allows users without the Execute Code Permission to configure the Service in installations that use fine-grained authorization and have the optional TinkerpopClientService installed. Apache NiFi installations that do not have the nifi-other-graph-services-nar installed are not subject to this vulnerability. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Apache NiFi 安全漏洞
Vulnerability Description
Apache NiFi是美国阿帕奇(Apache)基金会的一套数据处理和分发系统。该系统主要用于数据路由、转换和系统中介逻辑。 Apache NiFi 2.0.0-M1版本至2.8.0版本存在安全漏洞,该漏洞源于可选扩展组件TinkerpopClientService缺少Restricted注解,可能导致未授权用户配置服务并执行Groovy脚本。
CVSS Information
N/A
Vulnerability Type
N/A