-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from debug logging of Parameter Context values during flow synchronization. The GitHub patch shows removal of a code block in VersionedFlowSynchronizer.java that: 1) Checked if debug logging was enabled 2) Collected parameter values 3) Logged them using logger.debug(). This matches the vulnerability description where authorized admins could enable debug logging to expose sensitive parameters. The affected function updateParameterContext() was modified in the patch, confirming it as the vulnerable location.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.nifi:nifi-framework-core | maven | >= 1.16.0, < 1.28.1 | 1.28.1 |
| org.apache.nifi:nifi-framework-core | maven | >= 2.0.0-M1, <= 2.0.0-M4 | 2.0.0 |
Ongoing coverage of React2Shell