GHSA-rvp4-r3g6-8hxq
MEDIUMCVE-2022-26850org.apache.nifi.authentication.single.user.writer.StandardLoginCredentialsWriter contains a local information disclosure vulnerability due to writing credentials (username and password) to a file that is readable by all other users on unix-like systems. On unix-like systems, the system's temporary directory is shared between all users on that system. As such, files written to that directory withou
- Affected
- >=1.14.0, <1.16.0
- Fixed in
- 1.16
- Weakness
- CWE-522
- Published
- 2022-06-20
- Source
- github