CVE-2017-7667

HIGH

Apache NiFi <1.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99018

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-346
Status published
Products (10)
apache/nifi 1.0.0
apache/nifi 1.0.1
apache/nifi 1.1.0
apache/nifi 1.1.1
apache/nifi 1.1.2
apache/nifi 1.2.0
apache/nifi < 0.7.3
Apache Software Foundation/Apache NiFi 0.0.1 to 0.7.3
Apache Software Foundation/Apache NiFi 1.0.0 to 1.2.0
org.apache.nifi/nifi 0 - 0.7.4Maven
Published Jun 12, 2017
Tracked Since Feb 18, 2026