In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Nifi
APPApache0.7.00.7.11.1.01.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
Related vulnerabilities
CVE-2018-1309CRITICAL9.8PL ✓same product
Apache NiFi: XXE w procesorze SplitXML umożliwia RCE lub ujawnienie danych
CVE-2017-15697CRITICAL9.8PL ✓same product
RCE przez nagłówek X-ProxyContextPath w Apache NiFi
CVE-2026-62354HIGH7.7PL ✓same product
Apache NiFi: nieautoryzowana walidacja Parameter Context przez użytkownika read-only
CVE-2026-68981HIGH8.8PL ✓same product
Apache NiFi: atak typu zip bomb przez gzip-encoded HTTP request
CVE-2026-44914HIGH7.5same product
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extensio...