GHSA-7mqj-xgf8-p59v
MEDIUMCVE-2024-45477Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Ap
- Affected
- >=1.10.0, <1.28.0
- Fixed in
- 2.0.0-M4
- Weakness
- CWE-79
- Published
- 2024-10-29
- Source
- github