CVE-2016-8748
medium
CVSS v3
5.4
CVSS v2
3.5
VIR risk
5.4
Description
Cross-site Scripting in Apache NiFi
Predictions
Exploit likelihood
64%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@apache.org — https://nifi.apache.org/security.html#CVE-2016-8748
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.nifi:nifi | <1.0.1 | 1.0.1 |
| Maven | org.apache.nifi:nifi | >=1.1.0,<1.1.1 | 1.1.1 |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.