CRITICAL🇵🇱 Wersja polska

CVE-2017-5636

CVSS 9.8v3.0pub. 2017-10-19upd. 2026-05-13

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Nifi

    APP
    Apache
    0.7.00.7.11.1.01.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2018-1309CRITICAL9.8PL ✓same product

Apache NiFi: XXE w procesorze SplitXML umożliwia RCE lub ujawnienie danych

CVE-2017-15697CRITICAL9.8PL ✓same product

RCE przez nagłówek X-ProxyContextPath w Apache NiFi

CVE-2026-62354HIGH7.7PL ✓same product

Apache NiFi: nieautoryzowana walidacja Parameter Context przez użytkownika read-only

CVE-2026-68981HIGH8.8PL ✓same product

Apache NiFi: atak typu zip bomb przez gzip-encoded HTTP request

CVE-2026-44914HIGH7.5same product

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extensio...