GHSA-v4p2-2w39-mhrj
HIGHCVE-2025-66524Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without filtering. Unfiltered Java object deserialization does not provide protection against crafted state info
- Affected
- >=1.20.0, <2.7.0
- Fixed in
- 2.7.0
- Weakness
- CWE-502
- Published
- 2025-12-19
- Source
- github