Apache NiFi Vulnerabilities Lead to Authorization Bypass and Memory Issues
Article Content
- •Four critical vulnerabilities disclosed in Apache NiFi's Web API.
- •Affected versions include 1.5.0 through 2.10.0; upgrade to 2.11.0 is recommended.
- •Exploitation could lead to unauthorized access and memory exhaustion.
Apache NiFi has disclosed four critical vulnerabilities affecting its Web API and Parameter Context authorization controls. Users are urged to upgrade to version 2.11.0 to mitigate risks of authorization bypass, unauthorized configuration changes, and memory exhaustion. The vulnerabilities allow attackers to exploit the system via specially crafted gzip-compressed HTTP requests, leading to potential unauthorized deletion of assets and code execution in specific deployments. Affected versions range from 1.5.0 to 2.10.0. The vulnerabilities have been classified with high severity due to their potential impact on system integrity and availability. Users are advised to take immediate action to secure their installations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…