Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CABgFv25Fcdzf-xEFpT4_AQZkynZBHXD6EQRcCmLwCqrV+5NC7w@mail.gmail.com>
Date: Tue, 11 Mar 2025 16:12:00 +0100
From: Pierre Villard <pvillard@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2025-27017: Apache NiFi: Potential Insertion of MongoDB Password
 in Provenance Record

Affected versions:

- Apache NiFi 1.13.0 through 2.2.0
- Apache NiFi 2.3.0 unaffected

Description:

Apache NiFi 1.13.0 through 2.2.0 includes the username and password
used to authenticate with MongoDB in the NiFi provenance events that
MongoDB components generate during processing. An authorized user with
read access to the provenance events of those processors may see the
credentials information. Upgrading to Apache NiFi 2.3.0 is the
recommended mitigation, which removes the credentials from provenance
event records.

This issue is being tracked as NIFI-14272

Credit:

Robert Creese (finder)

References:

https://nifi.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-27017
https://issues.apache.org/jira/browse/NIFI-14272

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.