Apache NiFi Vulnerabilities Enable Authorization Bypass Attacks
Apache NiFi users should upgrade to version 2.11.0 after the project disclosed four security vulnerabilities affecting the NiFi Web API and Parameter Context authorization controls. The flaws could enable authorization bypass, unauthorized configuration changes, validation abuse, memory exhaustion, and, in specific deployments, code execution through manipulated parameter values. The security issues affect Apache NiFi versions […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
