Vulnerability Description
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | <= 1.0.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95621Third Party AdvisoryVDB Entry
- https://nifi.apache.org/security.html#CVE-2016-8748Issue TrackingMitigationVendor Advisory
- http://www.securityfocus.com/bid/95621Third Party AdvisoryVDB Entry
- https://nifi.apache.org/security.html#CVE-2016-8748Issue TrackingMitigationVendor Advisory
FAQ
What is CVE-2016-8748?
CVE-2016-8748 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being...
How severe is CVE-2016-8748?
CVE-2016-8748 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8748?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nifi.