Insertion of Sensitive Information into Log File Affecting org.apache.nifi:nifi-framework-core package, versions [1.16.0, 1.28.1)[2.0.0-M1, 2.0.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insertion of Sensitive Information into Log File vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHENIFI-8400289
  • published21 Nov 2024
  • disclosed21 Nov 2024
  • creditDavid Handermann

Introduced: 21 Nov 2024

NewCVE-2024-52067  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade org.apache.nifi:nifi-framework-core to version 1.28.1, 2.0.0 or higher.

Overview

org.apache.nifi:nifi-framework-core is a system to process and distribute data.

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File due to the debug logging feature during the flow synchronization process. An attacker can cause the application to write Parameter names and values to the application log.

Notes:

1)Parameter Context values may contain sensitive information depending on application flow configuration.

  1. This is only exploitable if the attacker has administrative privileges to expose sensitive information by enabling debug logging, which leads to the logging of sensitive Parameter Context values.

CVSS Scores

version 4.0
version 3.1