maven package report

Is org.apache.nifi:nifi-single-user-utils safe?

1 known vulnerability, worst severity MEDIUM.

cvss
5.0

how bad it is if exploited, out of 10

epss
1.5%

chance of exploitation in the next 30 days

xyz score
2.2

CyberXYZ composite, out of 10

fig. 01 — GHSA-rvp4-r3g6-8hxq, the advisory selected below

// advisories

GHSA-rvp4-r3g6-8hxq

MEDIUMCVE-2022-26850

org.apache.nifi.authentication.single.user.writer.StandardLoginCredentialsWriter contains a local information disclosure vulnerability due to writing credentials (username and password) to a file that is readable by all other users on unix-like systems. On unix-like systems, the system's temporary directory is shared between all users on that system. As such, files written to that directory withou

Affected
>=1.14.0, <1.16.0
Fixed in
1.16
Weakness
CWE-522
Published
2022-06-20
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 03:34 UTC. The most recent advisory here was published 2022-06-20. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.apache.nifi:nifi-single-user-utils safe? maven package security report | CyberXYZ