maven package report

Is org.apache.nifi:nifi-web-ui safe?

2 known vulnerabilities, worst severity MEDIUM.

cvss
4.6

how bad it is if exploited, out of 10

epss
0.70%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-7mqj-xgf8-p59v, the advisory selected below

// advisories

GHSA-7mqj-xgf8-p59v

MEDIUMCVE-2024-45477

Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Ap

Affected
>=1.10.0, <1.28.0
Fixed in
2.0.0-M4
Weakness
CWE-79
Published
2024-10-29
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:47 UTC. The most recent advisory here was published 2024-10-29. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.apache.nifi:nifi-web-ui safe? maven package security report | CyberXYZ