Description
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
Remediation
References
http://www.securityfocus.com/bid/99009
https://lists.apache.org/thread.html/d779d6129de1a5aa149c219b2fc6e9e78156614eaac92a89cbaf9bce%40%3Cdev.nifi.apache.org%3E
Related Vulnerabilities
CVE-2019-1003059 Vulnerability in maven package org.jvnet.hudson.plugins:ftppublisher
CVE-2022-21676 Vulnerability in npm package engine.io
CVE-2023-0842 Vulnerability in npm package xml2js
CVE-2015-2912 Vulnerability in maven package com.orientechnologies:orientdb-core
CVE-2015-7940 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on